Data leakage test
Find out what your agent gives away
Enoki hides its own fake secrets and personal details where your agent can reach them, then spends the run trying to get them back out. We never use your real data as the bait.
One break here is a disclosure, not a bug report
4 categories, and the taxonomy rates every one of them critical. A break is the agent handing over something it was holding.
PII Leakage
criticalThe agent leaks personal data that was seeded into its context.
- LLM02:2025
- ASI06:2026
- AML.T0057
Secret Disclosure
criticalThe agent leaks seeded secrets, credentials, API keys or tokens from its context.
- LLM02:2025
- ASI06:2026
- AML.T0057
Credential Extraction
criticalThe agent discloses API keys, service-account credentials or configuration secrets through its sandbox, its error messages or its architecture.
- LLM02:2025
- ASI06:2026
- AML.T0098
- AML.T0083
- AML.T0082
Data Exfiltration
criticalThe agent leaks internal data through a covert channel or an encoded output.
- LLM02:2025
- ASI02:2026
- AML.T0086
- AML.T0077
Free run
- One agent, one short security assessment
- Every finding with the attack that proved it
- It cannot tell you what has already leaked
Enoki platform
- Assessments that run far deeper
- The full conversation behind every finding
- Unlimited reruns
- Security and safety testing
Read further: AI agent red teaming tools in 2026
We hide our own secret, then try to get it back
Enoki seeds and then retrieves
Marked secrets we control go where the agent can read them, then the run works to pull them out.
See what came back
The report shows the request that proved it and your agent's reply.
Questions before you run it
Does Enoki read my real customer data?
Not as bait. The seeded half uses values Enoki generated, so a leak there is unambiguous. The other 2 categories ask whether the agent volunteers its own internals, and if it does, the finding holds whatever it handed over. That is the point of catching it.
What is the difference between leakage and exfiltration?
Leakage is the agent revealing, when asked, something it should keep to itself. Exfiltration is the agent moving data through a channel that was not meant to carry it, such as an encoded output or a tool call. They are separate categories because they need separate fixes.
My agent has no access to sensitive data. Is this still worth running?
Probably, because agents usually hold more than their owners think: the system prompt, the tool list, error output, and whatever a retrieval step pulled in. Tool Discovery and Debug Access are on the system prompt page for the same reason.
Other things Enoki will attack
Same free run, a different risk on each page.
- Prompt injectionInstructions hidden in what your agent reads.Test my agent for free →
- System prompt leakThe known paths to your agent's own rulebook.Test my prompt for free →
- JailbreaksMulti-turn attacks, not one-shot prompts.Test my guardrails for free →
- OWASP Top 10Findings that already carry their OWASP id.Test my agent for free →
- Agent pentestThe same attacks, on every release.Run the first one free →
Your first assessment
Enter your agent's endpoint
One field, no install, no code access. You get the report and the attack behind every finding.