Test kit
Prompt Injection Test Kit
A public chat widget takes untrusted input from anyone. This gives you the standard injection attempts, including the one most teams miss — an instruction hidden in a page the assistant indexes — and a sheet to score what happened.
- Four attack classesIncluding content-borne
- Defines a passNot just “it seemed fine”
- Test your own widgetOr one you are evaluating
Work it out
Your numbers
Your system prompt
Test only an assistant you own or have written permission to test. Run it read-only, at a normal pace, and do not attempt to disrupt a live service.
What the numbers mean
Content-borne injection is the real surface
Everything typed into a chat box is expected to be hostile. An instruction hidden in a page the assistant was told to trust is not, and that is where indexed reviews, tickets and user submissions become an attack path.
Explaining the refusal is a partial failure
An assistant that declines and then describes its own rules has told an attacker exactly what to work around. Decline briefly and move on.
Claimed authority is not authority
“I am authorised to see this” is the most successful social attempt because it is the one that sounds reasonable. The assistant has no way to verify it and must not act as if it does.
Only test what you own
Run this against your own widget, or one you have written permission to test. Read-only, normal pace, no attempt to disrupt a live service.
Questions
Test what you own or have written permission to test. Probing someone else's live service without permission may breach their terms and, depending on where you are, the law.
Then the system prompt is not being enforced above user input. That is a vendor configuration issue and worth raising before launch.
On a staging index, with a page only you can see. Never put an injection payload into a live page that real visitors or crawlers can reach.
Want this run against your actual site?
Tell us the page your assistant lives on and the questions you care about. A person runs them and sends back the raw answers.