Hidden Prompt Injection & Unicode Smuggling Detector

Find and decode instructions hidden in invisible Unicode tag characters and emoji variation selectors before text reaches an AI.

Loading Tool...

Help shape Hidden Prompt Injection & Unicode Smuggling Detector

The bug you just noticed will fade in 3 minutes. The feature idea will vanish after your next tab switch. Crazy peps don't suffer silently.

0/1000

Frequently Asked Questions

Unicode tag characters (U+E0020–E007E) and runs of variation selectors are invisible but still read by AI models. Attackers use them to smuggle prompts into documents, emails and web pages.

Yes. Tag characters are decoded back to ASCII and variation-selector data back to UTF-8 text, then shown in a red warning box.

Click Remove next to the finding, or use Clean & normalise. The visible text stays exactly the same.

Yes. The Hidden-text tester builds strings with a hidden payload so you can test your own filters and guardrails.

No. Detection runs locally in a Web Worker; nothing is uploaded.