Prompt Injection Checker
Runs locally in your browserCheck prompts, external context, and agent boundaries for injection risk
Input
Paste each part into its own field. One field is enough to start.
+ External / RAG Context
+ Tool Output
+ Agent capabilities
Safeguards enforced outside the prompt
Turn these on only when your application enforces them in code. They are declarations, not proof.
What it checks
The checker reviews system instructions, user input, retrieved RAG context and tool output separately. It flags instruction overrides, fake role blocks, prompt and secret extraction, commands hidden in HTML or Markdown, invisible or encoded text, and missing trust boundaries between instructions and data.
How to use it
Paste each part into its own field, enable the capabilities your agent really has, and select Analyze. Open a finding to see its escaped evidence, then copy the mitigations or the full report. Presets demonstrate common attacks and a hardened baseline.
How severity works
The same text is rated higher in untrusted sources than in your own instructions. High-impact capabilities such as shell execution, writes, email, deployment or secrets access, or data access combined with an outbound channel, raise related findings. Capabilities alone are reported as exposure, not as an injection.
Limits and privacy
Prompts are analyzed in your browser and are not uploaded, stored or sent to analytics. Each field is scanned up to 32,768 characters and decoding is bounded. Rules focus on English wording and Unicode structure, so new attacks and other languages can be missed, and harmless quotes can be flagged. Treat the result as a review aid, not a guarantee. To check prompts for secrets and personal data, use the AI Prompt PII & Secret Leak Scanner.
