Prompt injection test
Paste your AI agent's system prompt and tool list. The test checks which defences against prompt injection are present and which are missing, rates what that exposes, and tells you exactly what to add to the prompt and what to enforce outside it.
Free, no sign-up, nothing leaves your browser. Plain rules, no AI model: the page is blocked from making network requests.
Your prompt injection test result
Lethal trifecta: this agent reads untrusted content, reaches private data and can send data out. An injected instruction can chain all three; exfiltration findings are rated critical.
Attack families
| Attack family | Status | Defence score | Defences found |
|---|
Findings and fixes
Defences already in place
Confirm it on the running agent
This result reads the design, not the model's behaviour. In a test environment with test data, plant a harmless marker string with an instruction to repeat it in each channel the agent reads (the chat, a document, a web page, an email, a tool result). If the marker shows up in a reply, or a tool is called because of planted text, that channel is open. Re-run after every prompt or tool change.
What the test checks
Eight attack families, each with the defences that blunt it. A family that can't reach your agent (for example tool-call exfiltration when no tool sends data out) is marked not exposed and left out of the score.
- Instruction override: A message tells the model to ignore its instructions and do something else.
- Role-play jailbreak: The request is wrapped in a story, game, persona or hypothetical so the rules seem not to apply.
- Data exfiltration through tool calls: An injected instruction makes the agent call a tool that sends private data to the attacker.
- Exfiltration through Markdown images and links: The agent is made to output an image or link whose address carries data; displaying it sends the data to the attacker's server.
- Indirect injection through retrieved content: Instructions hidden in a web page, email, document or tool result are read by the agent and followed.
- Secret and system prompt disclosure: The user coaxes the model into repeating its instructions, including anything sensitive written in them.
- Delimiter and role confusion: Fake system tags, closing quotes or role labels make injected text look like it came from the developer.
- Encoded, translated and split payloads: The instruction is hidden with Base64, another language, invisible characters or split across messages, to slip past filters.
It reads your prompt for defences (precedence rules, scope limits, data boundaries, approval steps, allow-lists, output rules) and your tool list for exposure (tools that read outside content, reach private data, send data out or act). No AI model is involved: the same input always gives the same result.
Questions
Is my system prompt sent anywhere?
No. The test runs in this page with plain rules. No AI model is called, and the page's security policy blocks every outgoing request (connect-src 'none'), so nothing you paste can leave the browser or be stored.
What does the defence score measure?
For each attack family that applies to your agent, the test adds up the weights of the defences it finds in your prompt and tool list (0 to 100). The overall score is the average over those families. Every point traces to a named defence.
Does a high score mean my agent can't be injected?
No. The test reads the design; it can't see how the model behaves or what your tools enforce. Prompt rules are requests the model can be talked out of. Confirm the result on the running agent and back every prompt rule with a control in code.
Which tool formats can I paste?
Anthropic tool definitions, OpenAI function or tool definitions, an MCP tools/list result, or one tool per line written as name: description.
Which attack families are tested?
Instruction override; Role-play jailbreak; Data exfiltration through tool calls; Exfiltration through Markdown images and links; Indirect injection through retrieved content; Secret and system prompt disclosure; Delimiter and role confusion; Encoded, translated and split payloads.
Prompt injection guides
- What is prompt injection?: What prompt injection is, where the term comes from, and how OWASP, NIST, MITRE ATLAS and the UK NCSC describe it.
- Prompt injection examples: Real, documented prompt injection examples.
- Indirect prompt injection: Indirect prompt injection explained.
- How to prevent prompt injection attacks: How to prevent prompt injection attacks.
- Prompt injection vs jailbreak: Prompt injection vs jailbreaking.
- OWASP LLM01: prompt injection: OWASP LLM01.