Jailbreak test
Your guardrails hold for one message. What about a whole conversation?
Most tests send your agent one message and check the reply. The attacks that actually work build up over a long conversation, one message at a time, until the agent has agreed to something it would have refused at the start. Enoki keeps the conversation going until the agent breaks.
An agent that refuses everything is also broken
2 categories for the agent that gives way, and 1 for the agent hardened until it stopped being useful.
System Prompt Override
highThe agent ignores its system instructions and follows the attacker's instructions instead.
- LLM01:2025
- ASI01:2026
- AML.T0051.000
Hijacking
highThe agent is redirected to perform a second task the attacker chose, instead of the one it was asked for.
- LLM01:2025
- ASI01:2026
- AML.T0051.000
- AML.T0051.001
Over Refusal
lowThe agent refuses legitimate, benign requests. A false positive, and the other way an agent can be broken.
Free run
- One agent, one short security assessment
- Every finding with the attack that proved it
- A sample of multi-turn attacks, not the full library
Enoki platform
- Assessments that run far deeper
- The full conversation behind every finding
- Unlimited reruns
- Security and safety testing
Read further: Single-turn, multi-turn and dynamic attacks
A real conversation, turn by turn
Enoki holds a conversation
Each turn is chosen from what the agent said last, rather than replayed from a list.
See the attack that worked
The report shows the request that proved it and your agent's reply.
Questions before you run it
We already ran a single-turn tool and passed. Why run this?
Because a single-turn pass and a multi-turn pass are different claims. A one-shot prompt never builds the context that most working jailbreaks depend on. Our write-up on single, multi-turn and dynamic attacks sets out the difference.
Why is over-refusal in a jailbreak test?
Because the cheap way to pass a jailbreak test is to refuse everything, and an agent that refuses its own users is broken in a way that no security report usually catches. Enoki grades both directions so hardening cannot quietly destroy the product.
How many turns does it run?
The free run is deliberately short. That is the trade it makes for costing nothing, and it is why the free-run box above calls it a sample.
Other things Enoki will attack
Same free run, a different risk on each page.
- Prompt injectionInstructions hidden in what your agent reads.Test my agent for free →
- System prompt leakThe known paths to your agent's own rulebook.Test my prompt for free →
- Data leakageSecrets we hide, and whether they come back.Test my agent for free →
- OWASP Top 10Findings that already carry their OWASP id.Test my agent for free →
- Agent pentestThe same attacks, on every release.Run the first one free →
Your first assessment
Enter your agent's endpoint
One field, no install, no code access. You get the report and the attack behind every finding.