Promptinel – A Security Scanner for Prompts
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.

URL injection bypassed canary tokens and schema validation simultaneously.
Developers building LLM pipelines with untrusted input
Lakera Guard · PromptArmor · Rebuff
Deterministic prompt linter flags injection, exfiltration, obfuscation before LLM runs—treats prompts as executable code.
Demonstrates RCE in AI agents by bypassing untrusted content tags via fake redirects.
Local secret redaction for AI IDEs when cloud-based scanners can't intercept prompts.
Research framework with published paper, not a production red-teaming tool.
GPT-5.4 executes untrusted code from fetched pages despite security countermeasures in place.
Persistent agent memory for architectural rules via MCP—actually stops agents from redoing weeks of work.