Prompt injection & hidden text scanner
Before you paste untrusted content into an AI tool, scan it. This checks for hidden characters, white-on-white text, and common prompt-injection attack patterns. Free, private, in-browser.
🔒 100% private — in-browser
⚠️ heuristic — not a guarantee
Ready to scan
Paste text on the left. We'll flag hidden characters, injection patterns, and hidden-text HTML signals.
What it checks
- Hidden characters — zero-width spaces, joiners, BOMs, and other invisible Unicode.
- Prompt-injection patterns — "ignore previous instructions", role jailbreaks, prompt-exfiltration asks, system-marker spoofing.
- Hidden-text HTML signals — white text, zero opacity, display:none, off-screen positioning.
Honest limits
- This is a heuristic — it catches common patterns, not every possible attack. No scanner guarantees safety.
- It flags signals; a flag isn't proof of malicious intent (and no flag isn't proof of safety).