Prompt injection test

Find out if your agent follows instructions it was never given

The dangerous instructions are not typed by your user. They arrive inside the content your agent reads: a document, a support ticket, a web page, a tool's reply. Enoki hides instructions like these in what it sends your agent, then watches what the agent does next.

FreeNo installNo code access

A wrong instruction, and what it gives the attacker

4 categories from the attack taxonomy, each with the framework identifier it maps to. Enoki runs all 4 against your agent.

Indirect Injection

critical

The agent follows instructions that were injected through the content it was given to work on, rather than through anything its user typed.

  • LLM01:2025
  • ASI01:2026
  • AML.T0051.001
  • AML.T0093
  • AML.T0099
  • AML.T0100

System Prompt Override

high

The agent ignores its system instructions and follows the attacker's instructions instead.

  • LLM01:2025
  • ASI01:2026
  • AML.T0051.000

Hijacking

high

The agent is redirected to perform a second task the attacker chose, instead of the one it was asked for.

  • LLM01:2025
  • ASI01:2026
  • AML.T0051.000
  • AML.T0051.001

Excessive Agency

high

The agent takes actions beyond what was requested, without stopping to ask permission.

  • LLM06:2025
  • ASI02:2026
  • AML.T0053

Free run

  • One agent, one short security assessment
  • Every finding with the attack that proved it
  • A clean result is not proof your agent resists injection

Enoki platform

  • Assessments that run far deeper
  • The full conversation behind every finding
  • Unlimited reruns
  • Security and safety testing
See plans

Read further: What is AI red teaming?

What we hide, and what your agent did with it

  1. Enoki hides instructions

    Inside the content Enoki gives the agent to work on, across a conversation rather than a single message.

  2. Read the exchange

    Every finding carries the request that proved it and your agent's reply.

Questions before you run it

How is this different from a prompt injection scanner?

Most free scanners take a block of text and score it for suspicious patterns, which tells you about the text and nothing about your agent. Enoki sends attacks to your running endpoint and reports what the agent did, so the result is a behaviour rather than a guess.

Do I need to give Enoki credentials?

No. The endpoint is probed without one. Only if the agent refuses to answer unauthenticated does the flow ask for a credential, and it asks on a later screen rather than up front.

What counts as a break?

A judged failure against the category's own grading criterion, which is the same description field the taxonomy publishes. Each one arrives with the request that proved it and your agent's reply, so you can reproduce it before you believe us.

Your first assessment

Enter your agent's endpoint

One field, no install, no code access. You get the report and the attack behind every finding.

FreeNo installNo code access