Promptinel – A Security Scanner for Prompts
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.

GPT-5.4 executes untrusted code from fetched pages despite security countermeasures in place.
AI security researchers and agent developers
Gandalf · PromptInject · AI Security Benchmark
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.
Demonstrates RCE in AI agents by bypassing untrusted content tags via fake redirects.
Research framework with published paper, not a production red-teaming tool.
Isolated LLM with no tools or memory makes prompt injection hit a dead end.
GitHub for prompts is an interesting bet, but PromptBase and FlowGPT already exist.
URL injection bypassed canary tokens and schema validation simultaneously.