Prompt injection test
Find out if your agent follows instructions it was never given
The dangerous instructions are not typed by your user. They arrive inside the content your agent reads: a document, a support ticket, a web page, a tool's reply. Enoki hides instructions like these in what it sends your agent, then watches what the agent does next.
A wrong instruction, and what it gives the attacker
4 categories from the attack taxonomy, each with the framework identifier it maps to. Enoki runs all 4 against your agent.
Indirect Injection
criticalThe agent follows instructions that were injected through the content it was given to work on, rather than through anything its user typed.
- LLM01:2025
- ASI01:2026
- AML.T0051.001
- AML.T0093
- AML.T0099
- AML.T0100
System Prompt Override
highThe agent ignores its system instructions and follows the attacker's instructions instead.
- LLM01:2025
- ASI01:2026
- AML.T0051.000
Hijacking
highThe agent is redirected to perform a second task the attacker chose, instead of the one it was asked for.
- LLM01:2025
- ASI01:2026
- AML.T0051.000
- AML.T0051.001
Excessive Agency
highThe agent takes actions beyond what was requested, without stopping to ask permission.
- LLM06:2025
- ASI02:2026
- AML.T0053
Free run
- One agent, one short security assessment
- Every finding with the attack that proved it
- A clean result is not proof your agent resists injection
Enoki platform
- Assessments that run far deeper
- The full conversation behind every finding
- Unlimited reruns
- Security and safety testing
Read further: What is AI red teaming?
What we hide, and what your agent did with it
Enoki hides instructions
Inside the content Enoki gives the agent to work on, across a conversation rather than a single message.
Read the exchange
Every finding carries the request that proved it and your agent's reply.
Questions before you run it
How is this different from a prompt injection scanner?
Most free scanners take a block of text and score it for suspicious patterns, which tells you about the text and nothing about your agent. Enoki sends attacks to your running endpoint and reports what the agent did, so the result is a behaviour rather than a guess.
Do I need to give Enoki credentials?
No. The endpoint is probed without one. Only if the agent refuses to answer unauthenticated does the flow ask for a credential, and it asks on a later screen rather than up front.
What counts as a break?
A judged failure against the category's own grading criterion, which is the same description field the taxonomy publishes. Each one arrives with the request that proved it and your agent's reply, so you can reproduce it before you believe us.
Other things Enoki will attack
Same free run, a different risk on each page.
- System prompt leakThe known paths to your agent's own rulebook.Test my prompt for free →
- Data leakageSecrets we hide, and whether they come back.Test my agent for free →
- JailbreaksMulti-turn attacks, not one-shot prompts.Test my guardrails for free →
- OWASP Top 10Findings that already carry their OWASP id.Test my agent for free →
- Agent pentestThe same attacks, on every release.Run the first one free →
Your first assessment
Enter your agent's endpoint
One field, no install, no code access. You get the report and the attack behind every finding.