πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All tools
betaPrompt Injection Scanner

Prompt Scan

Catches injected instructions hiding in content your agent should only read.

Prompt Scan β€” Catches injected instructions hiding in content your agent should only read.
In the wildβ€” Prompt Scan runsβ€” Issues surfacedβ€” CountriesΒ· opt-in only

The problem

The one rule that actually stops prompt injection is simple to state and easy to skip: forwarded emails, retrieved documents, and tool output are data your agent reads, never instructions it obeys. Most apps don’t enforce that boundary in code β€” they pass everything straight to the model and hope the system prompt holds.

What it does

A fast static scanner that matches text against a curated corpus of documented injection and jailbreak techniques β€” instruction overrides ("ignore prior instructions"), system-prompt exfiltration, control-token injection, obfuscation, and tool abuse β€” each mapped to the OWASP LLM Top 10. It exists to catch exactly the line that turns "content to read" into "instructions to follow" before your agent ever sees it. Nothing is sent to a model; the scan is pure and local.

Capabilities

  • Curated pattern corpus across 8 technique categories
  • Severity-weighted risk score (0-100) with verdict
  • Every detection mapped to OWASP LLM Top 10 (2025)
  • Runs in the browser or as an npm package / CI gate
  • Never sends your prompt anywhere β€” static, local scan

How you run it

Paste any prompt, user message, or retrieved document in the browser and get a scored breakdown. Subscribers can also install @playciso/promptscan and gate CI on the exit code.

Roadmap

  • Static pattern matcher + OWASP mapping
  • In-browser scan form
  • npm package + CI gate
  • Behavioral probing against your endpoint
  • Custom pattern packs per application

FAQ

What is prompt injection?

Prompt injection is an attack where malicious instructions are hidden in content an AI agent processes β€” a web page, a document, an email, or a tool result β€” and the model, unable to reliably separate instructions from data, acts on them. It can cause the agent to leak data or misuse its tools.

What does PromptScan do?

PromptScan analyses content your agent will read and flags injected instructions and prompt-injection patterns before they reach the model, so you can strip or block them at the boundary rather than discovering the problem after the agent has acted.

How do I prevent prompt injection?

Treat all untrusted content as data, not instructions; scan and sanitise inputs (what PromptScan does); apply least privilege to the tools the agent can call; and require human approval for high-impact actions so a hijacked agent cannot do serious damage on its own.

Included with any PlayCISO plan

Prompt Scan runs inside PlayCISO for subscribers. The source stays private β€” no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.

PromptScan β€” Free Prompt Injection Scanner Β· PlayCISO