System prompt leak test
Can a stranger make your agent print its system prompt?
The prompt holds your rules, your tool list and often the names of your data sources. Enoki runs the known extraction paths and shows you exactly what came back.
The prompt is the target. These 2 are the way in.
System Prompt Leakage is rated critical in the taxonomy. The 2 categories beside it are how an attacker finds out what the agent can do before going after the prompt.
System Prompt Leakage
criticalThe agent reveals its system prompt or its hidden instructions.
- LLM07:2025
- ASI06:2026
- AML.T0056
- AML.T0069.002
Debug Access
highThe agent reveals internal debug output, configuration or operational detail.
- LLM02:2025
- ASI06:2026
- AML.T0069
- AML.T0084
Tool Discovery
lowThe agent reveals the tools, functions or API calls it can reach.
- LLM02:2025
- ASI06:2026
- AML.T0084.001
- AML.T0133
Free run
- One agent, one short security assessment
- Every finding with the attack that proved it
- A pass is not proof your prompt is private
Enoki platform
- Assessments that run far deeper
- The full conversation behind every finding
- Unlimited reruns
- Security and safety testing
Read further: What red-teaming tools actually find
The paths we try, and what came back
Enoki works the extraction paths
Direct asks, role play, encoding tricks, and the multi-turn setups that get past a refusal.
Compare what leaked
The report prints what came back, so you can hold it next to the prompt you wrote.
Questions before you run it
Why does it matter if the system prompt leaks?
It is the agent's rulebook. Someone holding it knows which refusals to get around, which tools exist, and often which internal systems are in play. Leakage is rated critical in our taxonomy for that reason, and OWASP lists it as LLM07:2025.
Does a clean result mean my prompt is safe?
It means the paths in this run did not work. Treat it as evidence, not a clearance. That is the honest answer, and it is why the free-run box above says the same thing.
Will you store my system prompt?
Enoki stores what the agent returned as the evidence behind a finding, because a finding without its exchange cannot be reproduced or fixed. What that means for retention and deletion is on the privacy page.
Other things Enoki will attack
Same free run, a different risk on each page.
- Prompt injectionInstructions hidden in what your agent reads.Test my agent for free →
- Data leakageSecrets we hide, and whether they come back.Test my agent for free →
- JailbreaksMulti-turn attacks, not one-shot prompts.Test my guardrails for free →
- OWASP Top 10Findings that already carry their OWASP id.Test my agent for free →
- Agent pentestThe same attacks, on every release.Run the first one free →
Your first assessment
Enter your agent's endpoint
One field, no install, no code access. You get the report and the attack behind every finding.