URL scans fetch the page server-side with one GET (SSRF-guarded, no private addresses). Text is scanned and discarded, never stored. Free, rate-limited per IP. Try an example.
What it looks for
- Instruction override — “ignore the previous instructions”, “you are now…”, fake system or developer messages.
- Indirect injection — content that addresses the AI and not the reader, text conditioned on “if you are an AI reading this”, fabricated tool results.
- Tool hijacking — instructions to call tools, change permissions, or chain actions the user did not ask for.
- Data exfiltration — instructions to send conversations, files or credentials somewhere; images whose URL carries data; known capture services.
- System-prompt extraction and jailbreak framing.
- Encoding tricks — zero-width and Unicode-tag smuggling, homoglyphs, hex, base64 and percent-encoded instructions.
Two profiles. The default is tuned for web pages and documents, so ordinary images, hashes and code samples do not trip it. The strict profile runs every rule as written, for tool arguments and outbound responses.
What a clean result means
That nothing obvious tripped. These are patterns, and a determined attacker can paraphrase past patterns. Use a scan as one layer: keep tools least-privilege, require confirmation for actions that send data or spend money, and treat every retrieved page as data, never as instructions.
How well it works, measured
On 1,714 top-site homepages it had never seen, the default profile raised a false alarm on 6 (0.35%). On labeled attacks it had never seen, it caught 38%; the strict profile caught 53%. Decoding tricks are its strongest area (78%), jailbreak framing its weakest (0–11%). The rules as originally written flagged 69% of ordinary homepages, which is why there are two profiles. Full write-up, method and per-site data.
Use it from an agent
curl "https://fetchgate.dev/v1/scan?url=https://example.com/some-page"
curl -X POST https://fetchgate.dev/v1/scan -H 'content-type: application/json' -d '{"text":"..."}'
Same free daily tier, then $0.003 per call over x402. Also an MCP tool: scan_for_prompt_injection at https://fetchgate.dev/mcp.