Promptinel – A Security Scanner for Prompts
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.

URL injection bypassed canary tokens and schema validation simultaneously.
Developers building LLM pipelines with untrusted input
Lakera Guard · PromptArmor · Rebuff
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.
Shifts prompt injection defense from input scanning to action gating.
Demonstrates RCE in AI agents by bypassing untrusted content tags via fake redirects.
Local secret redaction for AI IDEs when cloud-based scanners can't intercept prompts.
Research framework with published paper, not a production red-teaming tool.
GPT-5.4 executes untrusted code from fetched pages despite security countermeasures in place.