app.vercel.cloakcheck-wheat/cloakcheck

cloakcheck

Scan a page for hidden prompt-injection payloads targeting AI agents.

1.0.0
Version
remote
Transport
1
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 1 tools scanned
  • metadata: scanned

No findings.

Tools (1)

  • check_page_for_injection

    Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).