H/M::PROMPT FIREWALLLOCAL / DETERMINISTIC / NO UPLOAD

FREE BROWSER TOOL / INPUT QUARANTINE

Inspect text before an AI reads it.

Find known instruction overrides, invisible controls, encoded payloads and accidental secrets before they enter a model or tool-enabled agent.

RUNS IN THIS BROWSER MODEL CALLS: 0 TEXT UPLOAD: OFF RULESET::--
WHAT ARE YOU CHECKING?
TXT, MD, JSON, CSV OR HTML ยท 30K CHARACTERS
0 / 30,000 CHARACTERS

LOCAL PREFLIGHT / WAITING FOR INPUT

Treat external content as data, not authority.

The scanner checks visible and hidden text without sending it to another model.

  1. 01Choose the trust boundary
  2. 02Paste text or load a local file
  3. 03Review masked findings and controls

DEFENSE IN DEPTH / NOT A MAGIC FILTER

The scanner is one checkpoint, not the security boundary.

Current guidance from OWASP, NIST, Google and Microsoft converges on layered controls because prompt injection cannot be solved by keyword matching alone.

01

Separate instructions from data

Mark external content as untrusted and keep it outside privileged instructions.

02

Minimize tool authority

Allowlist tools, parameters and destinations; grant only the access required for the current task.

03

Confirm consequential actions

Require a person to approve payments, deletion, publication, external messages and permission changes.

04

Validate output and actions

Treat model output as untrusted before rendering it or passing it to another interpreter.

EXPLICIT LIMITS

A quiet result is not a safety certificate.

  • Novel, semantic, image-based and deeply obfuscated injection may not match these rules.
  • URLs are counted as context and are never labeled malicious only because they are external.
  • The tool does not execute links, decode files beyond text or inspect images and PDFs.
  • Rotate any real secret that may already have been exposed; redaction cannot revoke it.