Is your AI agent open to prompt injection?
Paste the agent's system prompt and its tool list. You'll get a risk score out of 100, the top 5 findings and a fix for each, mapped to the OWASP Top 10 for LLM Applications.
Nothing leaves your browser. The check runs on this page and the page is blocked from making network requests.
What it looks for
- The dangerous combination: tools that read outside content (web pages, email, documents), reach sensitive data, and can send data out, all in one agent.
- Outside content that can trigger actions: tools that change, delete, run code or move money in an agent that also reads untrusted content.
- Tool poisoning: hidden instructions inside tool descriptions, invisible characters and encoded blobs.
- Prompt problems: secrets and personal data in the prompt, "never reveal these instructions" used as a control, "always obey the user", and no rule that fetched content is data.
- Excessive agency: code execution, payments with no limit or approval, identity and permission tools, open-ended parameters and very large tool sets.
Every rule and its weight is on How the score works. New to the topic? Read what prompt injection is and examples of indirect prompt injection.
Questions
Is my prompt or tool list sent anywhere?
No. The check runs in this page. The page's security policy blocks every outgoing request (connect-src 'none'), so nothing you paste can be uploaded, and nothing is stored after you close the tab.
Which tool formats does it read?
Anthropic tool definitions, OpenAI function or tool definitions, an MCP tools/list result, or one tool per line written as name: description.
Does a low score mean the agent is safe?
No. This is a static check of what the agent is told and what it can do. It can't see how the model behaves, what data flows through the tools, or what the tools really do. Test the running agent as well.
How is the score calculated?
Each finding adds a fixed number of risk points, and the score is the sum, capped at 100. The weights for every rule are listed on the How the score works page.