Prompt Injection Scanner
Free prompt injection scanner. Detect instruction overrides, role hijacks, jailbreak modes, system-prompt exfiltration, fake chat delimiters and invisible Unicode in pasted prompts with offline heuristics and per-match highlighting. Runs in your browser.
Loading tool...
What is Prompt Injection Scanner?
The Prompt Injection Scanner checks pasted prompts, documents and chat messages against offline heuristics for the most common LLM attacks: instruction overrides, role and persona hijacks, known jailbreak modes, system-prompt and credential exfiltration, fake chat delimiters, and invisible Unicode characters. Each match gets a severity badge and the surrounding text so you can judge context, with a copyable report for review notes. Everything runs locally; no API calls, no uploads.
Key Benefits
- Instant offline scanning with no data leaving the page
- Severity-ranked matches so the dangerous stuff is visible first
- Invisible Unicode detection that human eyes always miss
- Highlighted excerpts for every match to judge context quickly
- A copyable report for security review notes and tickets
Common Use Cases
- β’Screening user-submitted prompts before an LLM automation runs
- β’Auditing web-scraped documents before feeding them to an assistant
- β’Teaching developers and writers what injection looks like
- β’Checking translated or copy-pasted content for hidden directives
- β’Adding a quick first-pass safety gate to internal AI tooling
How to Scan a Prompt for Injection
- Paste the untrusted text: Paste the prompt, document or chat message you want to check. Scanning happens instantly as you type, entirely in your browser.
- Read the severity counts: High-severity matches are classic attacks: instruction overrides, jailbreak modes, system-prompt or credential exfiltration. Medium matches need context, since phrases like act as can be innocent creative writing.
- Judge each match in context: Open each match to see the surrounding text, check the invisible-character list, then decide whether the text is safe to pass to your model. Copy the report for your review notes.
Key Features
- Detects instruction overrides and forget-everything phrasing
- Flags role hijacks, persona switches and known jailbreak modes
- Catches system-prompt and credential exfiltration requests
- Finds invisible Unicode such as zero-width and bidi-control characters
- Per-match severity badges with highlighted excerpts and a copyable report