cloakcheck
Scan a page for hidden prompt-injection payloads targeting AI agents.
- 1.0.0
- Version
- remote
- Transport
- 1
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 1 tools scanned
- metadata: scanned
No findings.
Tools (1)
check_page_for_injection
Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).