AI Security

Shadow Prompt Detection Tool

Detect hidden or shadow prompts in AI interactions.

Last reviewed by the Radiatus Cloud team

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Detect hidden prompts in AI content

Hidden or shadow prompts are instructions concealed in content, in white text, metadata, or an image, meant to manipulate an AI that processes it. This tool detects hidden or shadow prompts in AI interactions, so you can catch manipulation that a human would not see.

Why hidden prompts are a real threat

As AI systems process web pages, documents and images, attackers hide instructions in that content, invisible to a human but read by the model, to make it behave against its purpose, a form of indirect prompt injection. A page might contain hidden text telling an AI assistant to ignore its instructions or leak data. Detecting these concealed prompts before or as content is processed is a defensive control, because the human reviewing the content would never see them. This is defensive analysis to protect an AI system that ingests external content.

See what the model sees

The tool runs entirely in your browser, so nothing you paste, prompts, outputs or documents, is uploaded, which matters when the input is sensitive AI data or your own content.

Related tools

Frequently Asked Questions

What is a shadow or hidden prompt?

An instruction concealed in content, in white text, metadata or an image, invisible to a human but read by an AI that processes the content, meant to manipulate it.

How is this an attack?

It is indirect prompt injection: hidden instructions in content the model ingests make it behave against its purpose, such as leaking data or ignoring its rules.

Why can a human not catch it?

Because the prompt is concealed, in white text, metadata or an image, so a person reviewing the content sees nothing while the model reads the instruction.

Is this for my own system?

Yes. It is defensive analysis to protect an AI system that ingests external content from concealed manipulation.

Is my input uploaded?

No. The detection runs entirely in your browser.

Privacy & Security

Detection done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.