AI Agent Security Check

Is your AI agent open to prompt injection?

Paste the agent's system prompt and its tool list. You'll get a risk score out of 100, the top 5 findings and a fix for each, mapped to the OWASP Top 10 for LLM Applications.

Nothing leaves your browser. The check runs on this page and the page is blocked from making network requests.

What it looks for

Every rule and its weight is on How the score works. New to the topic? Read what prompt injection is and examples of indirect prompt injection.

Questions

Is my prompt or tool list sent anywhere?

No. The check runs in this page. The page's security policy blocks every outgoing request (connect-src 'none'), so nothing you paste can be uploaded, and nothing is stored after you close the tab.

Which tool formats does it read?

Anthropic tool definitions, OpenAI function or tool definitions, an MCP tools/list result, or one tool per line written as name: description.

Does a low score mean the agent is safe?

No. This is a static check of what the agent is told and what it can do. It can't see how the model behaves, what data flows through the tools, or what the tools really do. Test the running agent as well.

How is the score calculated?

Each finding adds a fixed number of risk points, and the score is the sum, capped at 100. The weights for every rule are listed on the How the score works page.

Sources