Proving ground · live against the production engine
Is your agent gullible?
Paste your agent's system prompt. We'll score how easy it is to hijack with indirect prompt injection — and show you exactly which technique classes it leaves open. Nothing leaves your browser until you click “Analyze”.
Paste the full system prompt. We check for protective patterns across seven injection technique classes.
0 characters · 0 words
🤖
Paste your agent's system prompt and click “Quick scan my agent”
Instant result — checks for protective patterns across seven technique classes.
What we check
- A Authority framing — does your prompt warn about forged admin voices?
- B Delimiter confusion — does it handle unknown tags and context boundaries?
- C Task hijack — does it stay focused on the user's real goal?
- D Obfuscation — does it resist leetspeak, base64, and hidden encoding?
- E Placement tricks — does it scan beyond the visible text?
- F Conditional triggers — does it resist state-dependent overrides?
How Elcaro scores
The Elcaro engine is built to catch all seven classes with near-zero false positives. On this same analyzer it scores 2% gullible — meaning its own prompt includes explicit quarantine, source verification, and anti-framing language across every technique class. Paste your prompt to see where yours stands.