Prompt-Injection Scanner

Check a web page or a block of text for instructions aimed at AI agents, before your agent reads it. 120 detection rules, including the text a human never sees: HTML comments, alt, title, aria and meta attributes.

URL scans fetch the page server-side with one GET (SSRF-guarded, no private addresses). Text is scanned and discarded, never stored. Free, rate-limited per IP. Try an example.

What it looks for

Two profiles. The default is tuned for web pages and documents, so ordinary images, hashes and code samples do not trip it. The strict profile runs every rule as written, for tool arguments and outbound responses.

What a clean result means

That nothing obvious tripped. These are patterns, and a determined attacker can paraphrase past patterns. Use a scan as one layer: keep tools least-privilege, require confirmation for actions that send data or spend money, and treat every retrieved page as data, never as instructions.

How well it works, measured

On 1,714 top-site homepages it had never seen, the default profile raised a false alarm on 6 (0.35%). On labeled attacks it had never seen, it caught 38%; the strict profile caught 53%. Decoding tricks are its strongest area (78%), jailbreak framing its weakest (0–11%). The rules as originally written flagged 69% of ordinary homepages, which is why there are two profiles. Full write-up, method and per-site data.

Use it from an agent

curl "https://fetchgate.dev/v1/scan?url=https://example.com/some-page"
curl -X POST https://fetchgate.dev/v1/scan -H 'content-type: application/json' -d '{"text":"..."}'

Same free daily tier, then $0.003 per call over x402. Also an MCP tool: scan_for_prompt_injection at https://fetchgate.dev/mcp.

Want the rules themselves? The Prompt-Injection Defenses Playbook ($39) is this 120-rule set as machine-readable JSON with every pattern, a dependency-free Python detector to run offline or in CI, false-positive notes per rule, and the permission-design layer that makes an injection survivable. To test your own defenses, the Test Corpus ($29) has 156 labeled attack cases.