Free tool / Prompt Injection Scanner

Prompt Injection Scanner

Inspect untrusted documents, user messages and tool results for suspicious model-directed instructions, exfiltration and tool-misuse patterns.

Current status: Live
Inspect untrusted AI content

Available now

Inspect untrusted documents, user messages and tool results for suspicious model-directed instructions, exfiltration and tool-misuse patterns.

Open the free tool
Bring
RAG documents, user messages or tool output as text, Markdown or JSON.
You get
Exact suspicious excerpts, severity, recommendations and a guarded JSON payload.
Know the limit
Pattern matching can miss novel attacks; a clean scan is never proof of safety.
Local by default

The five file and AI engineering tools run in your browser without an account, provider call or analytics. The workflow map can optionally hand a result to the project form only when you choose.

Use it for

Reviewing untrusted RAG documents, user messages and tool output before they enter a model context.

How it works

A versioned deterministic ruleset identifies exact suspicious passages, groups them by attack category and creates a guarded payload for review.

Example workflow

Scan a supplier document before indexing it, inspect every matched excerpt and still enforce model, tool and data permissions downstream.

Common questions
Does my input leave the browser?
The five file and AI engineering tools run in your browser without an account, provider call or analytics. The workflow map can optionally hand a result to the project form only when you choose.
Does the result prove the system is ready?
Pattern matching can miss novel attacks; a clean scan is never proof of safety.