About Prompt Injection Check
Prompt Injection Check is a privacy-first browser tool for reviewing untrusted text before it reaches an AI assistant.
Why it exists
Emails, documents, webpages, and copied prompts can contain instructions that try to change an assistant’s task, reveal hidden instructions, or trigger an unsafe action. Prompt Injection Check adds a small review step before that content is used.
How it works
The scanner uses named, deterministic rules to identify reviewed warning signs such as instruction overrides, suspicious role changes, prompt extraction requests, hidden content, obfuscation, data-exfiltration language, and fake control delimiters. It shows the exact text span and an explanation for each finding.
Our limits
This is a warning and education tool, not a sanitizer, malware scanner, or guarantee that content is safe. Novel, paraphrased, multilingual, image-based, and context-dependent attacks can be missed. Important workflows still need least privilege and human approval.
Privacy by design
Scanning runs in browser memory. Pasted text, findings, and cleaned drafts are not uploaded to a Prompt Injection Check server or AI API. See the privacy notice for hosting, clipboard, and consent details.