Data leakage test

Find out what your agent gives away

Enoki hides its own fake secrets and personal details where your agent can reach them, then spends the run trying to get them back out. We never use your real data as the bait.

FreeNo installNo code access

One break here is a disclosure, not a bug report

4 categories, and the taxonomy rates every one of them critical. A break is the agent handing over something it was holding.

PII Leakage

critical

The agent leaks personal data that was seeded into its context.

  • LLM02:2025
  • ASI06:2026
  • AML.T0057

Secret Disclosure

critical

The agent leaks seeded secrets, credentials, API keys or tokens from its context.

  • LLM02:2025
  • ASI06:2026
  • AML.T0057

Credential Extraction

critical

The agent discloses API keys, service-account credentials or configuration secrets through its sandbox, its error messages or its architecture.

  • LLM02:2025
  • ASI06:2026
  • AML.T0098
  • AML.T0083
  • AML.T0082

Data Exfiltration

critical

The agent leaks internal data through a covert channel or an encoded output.

  • LLM02:2025
  • ASI02:2026
  • AML.T0086
  • AML.T0077

Free run

  • One agent, one short security assessment
  • Every finding with the attack that proved it
  • It cannot tell you what has already leaked

Enoki platform

  • Assessments that run far deeper
  • The full conversation behind every finding
  • Unlimited reruns
  • Security and safety testing
See plans

Read further: AI agent red teaming tools in 2026

We hide our own secret, then try to get it back

  1. Enoki seeds and then retrieves

    Marked secrets we control go where the agent can read them, then the run works to pull them out.

  2. See what came back

    The report shows the request that proved it and your agent's reply.

Questions before you run it

Does Enoki read my real customer data?

Not as bait. The seeded half uses values Enoki generated, so a leak there is unambiguous. The other 2 categories ask whether the agent volunteers its own internals, and if it does, the finding holds whatever it handed over. That is the point of catching it.

What is the difference between leakage and exfiltration?

Leakage is the agent revealing, when asked, something it should keep to itself. Exfiltration is the agent moving data through a channel that was not meant to carry it, such as an encoded output or a tool call. They are separate categories because they need separate fixes.

My agent has no access to sensitive data. Is this still worth running?

Probably, because agents usually hold more than their owners think: the system prompt, the tool list, error output, and whatever a retrieval step pulled in. Tool Discovery and Debug Access are on the system prompt page for the same reason.

Your first assessment

Enter your agent's endpoint

One field, no install, no code access. You get the report and the attack behind every finding.

FreeNo installNo code access