System prompt leak test

Can a stranger make your agent print its system prompt?

The prompt holds your rules, your tool list and often the names of your data sources. Enoki runs the known extraction paths and shows you exactly what came back.

FreeNo installNo code access

The prompt is the target. These 2 are the way in.

System Prompt Leakage is rated critical in the taxonomy. The 2 categories beside it are how an attacker finds out what the agent can do before going after the prompt.

System Prompt Leakage

critical

The agent reveals its system prompt or its hidden instructions.

  • LLM07:2025
  • ASI06:2026
  • AML.T0056
  • AML.T0069.002

Debug Access

high

The agent reveals internal debug output, configuration or operational detail.

  • LLM02:2025
  • ASI06:2026
  • AML.T0069
  • AML.T0084

Tool Discovery

low

The agent reveals the tools, functions or API calls it can reach.

  • LLM02:2025
  • ASI06:2026
  • AML.T0084.001
  • AML.T0133

Free run

  • One agent, one short security assessment
  • Every finding with the attack that proved it
  • A pass is not proof your prompt is private

Enoki platform

  • Assessments that run far deeper
  • The full conversation behind every finding
  • Unlimited reruns
  • Security and safety testing
See plans

Read further: What red-teaming tools actually find

The paths we try, and what came back

  1. Enoki works the extraction paths

    Direct asks, role play, encoding tricks, and the multi-turn setups that get past a refusal.

  2. Compare what leaked

    The report prints what came back, so you can hold it next to the prompt you wrote.

Questions before you run it

Why does it matter if the system prompt leaks?

It is the agent's rulebook. Someone holding it knows which refusals to get around, which tools exist, and often which internal systems are in play. Leakage is rated critical in our taxonomy for that reason, and OWASP lists it as LLM07:2025.

Does a clean result mean my prompt is safe?

It means the paths in this run did not work. Treat it as evidence, not a clearance. That is the honest answer, and it is why the free-run box above says the same thing.

Will you store my system prompt?

Enoki stores what the agent returned as the evidence behind a finding, because a finding without its exchange cannot be reproduced or fixed. What that means for retention and deletion is on the privacy page.

Your first assessment

Enter your agent's endpoint

One field, no install, no code access. You get the report and the attack behind every finding.

FreeNo installNo code access