/injscan — Prompt Injection Scanner
Paste untrusted text — a web page, a tool result, a document headed for an LLM — and see the prompt-injection patterns hiding in it. Everything stays in your browser.
Load an example:
This is a lint, not a guarantee. It flags known patterns — instruction-override phrases, invisible / zero-width unicode, Unicode Tags-block smuggling, bidirectional (Trojan-Source) controls and image-based exfiltration. It cannot prove intent, and a determined attacker can evade it. Treat all external content as untrusted regardless of the result.