Prompt injection & hidden text scanner

Before you paste untrusted content into an AI tool, scan it. This checks for hidden characters, white-on-white text, and common prompt-injection attack patterns. Free, private, in-browser.

🔒 100% private — in-browser ⚠️ heuristic — not a guarantee
🧪
Ready to scan Paste text on the left. We'll flag hidden characters, injection patterns, and hidden-text HTML signals.

What it checks

  • Hidden characters — zero-width spaces, joiners, BOMs, and other invisible Unicode.
  • Prompt-injection patterns — "ignore previous instructions", role jailbreaks, prompt-exfiltration asks, system-marker spoofing.
  • Hidden-text HTML signals — white text, zero opacity, display:none, off-screen positioning.

Honest limits

  • This is a heuristic — it catches common patterns, not every possible attack. No scanner guarantees safety.
  • It flags signals; a flag isn't proof of malicious intent (and no flag isn't proof of safety).