Hidden Prompt Injection & Unicode Smuggling Detector
Find and decode instructions hidden in invisible Unicode tag characters and emoji variation selectors before text reaches an AI.
Help shape Hidden Prompt Injection & Unicode Smuggling Detector
The bug you just noticed will fade in 3 minutes. The feature idea will vanish after your next tab switch. Crazy peps don't suffer silently.
Frequently Asked Questions
Unicode tag characters (U+E0020–E007E) and runs of variation selectors are invisible but still read by AI models. Attackers use them to smuggle prompts into documents, emails and web pages.
Click Remove next to the finding, or use Clean & normalise. The visible text stays exactly the same.
Yes. The Hidden-text tester builds strings with a hidden payload so you can test your own filters and guardrails.
No. Detection runs locally in a Web Worker; nothing is uploaded.