Skip to main content

Prompt Injection Blocker

Read-only scanner for prompt-injection and LLM anti-analysis text in files before agent review.

This tool is meant for defensive intake: copied advisories, incident notes, third-party repositories, docs, issues, and fixtures that may contain text aimed at overriding an AI assistant or suppressing analysis.

It does not remove files, modify content, execute code, contact registries, or prove that content is safe.

Install

pipx install prompt-injection-blocker
# or
pip install prompt-injection-blocker

Python 3.9+. No runtime dependencies.

Usage

prompt-injection-blocker /path/to/project
prompt-injection-blocker /path/to/project --json
prompt-injection-blocker /path/to/project --report report.json

From a source checkout:

python -m prompt_injection_blocker /path/to/project
pip install -e ".[dev]" && pytest

Exit codes:

  • 0: no blocking promptware patterns found
  • 1: usage or runtime error
  • 2: blocking promptware patterns found

What It Flags

  • prompt-injection text that tries to override prior/system/developer instructions
  • text asking an agent to reveal secrets, hidden instructions, environment variables, or tokens
  • text trying to make an agent run commands or fetch external content
  • observability/tool-output text, such as fake Sentry resolutions, that tries to make an agent run package-manager diagnostics
  • LLM-targeted anti-analysis language that tells scanners not to report suspicious content
  • model-scanner refusal/null-result bait that tries to make an analysis pipeline stop before reaching suspicious payload code
  • Microsoft Copilot / AI-assistant links where a q= query parameter appears to carry private-context requests plus external exfiltration instructions
  • cryptographic context injection: encrypted page/tool content plus decrypt-in- sandbox language plus session data or URL-parameter exfiltration (Grok.com "summarize this page" class, Aug 2026). Ciphertext is not readable by input filters; decrypted tool output is untrusted.
  • broad repo-local agent instruction language that deserves review before opening a path in automated agents
  • recognized agent instruction, skill, and MCP configuration paths, even when their contents look benign, so provenance and scope receive human review
  • known phrase families after Unicode compatibility normalization, removal of invisible format characters, and defanging of simple HTML separators

The rules are intentionally conservative. A finding means "do not feed this raw text into an agent," not "this file is malware."

Safe Handling

  • Do not paste flagged text into agents in raw form.
  • Summarize or defang prompt-injection text before sharing with the team.
  • If this appears in a third-party repository, do not open the repo in agents or editors until reviewed.
  • If a test needs one of these markers, split or encode it so the test remains meaningful without carrying live promptware. This codebase stores all of its own detection markers split and joins them at runtime; keep that discipline when adding rules.
  • Treat model refusal as a failed analysis, not a clean result. Send the file through static checks, sandboxing, or human review instead of allowing a null response to pass.
  • Treat unfamiliar setup commands and anything they fetch at runtime as untrusted code. A clean text scan cannot establish what a later network response or package installation will execute.

Scope Limits

This scanner only checks text-like files and known phrase families. It will not detect every possible prompt-injection attempt, encoded payload, image-only instruction, runtime-fetched instruction, behavioral setup chain, or model-specific attack. Use it as one deterministic intake layer alongside provenance review, sandboxing, least-privilege tools, network controls, and human approval for consequential actions.

Metadata

Release files for prompt-injection-blocker 0.1.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for prompt-injection-blocker 0.1.5
File Size Uploaded
prompt_injection_blocker-0.1.5.tar.gz 16.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for prompt-injection-blocker 0.1.5
File Interpreter ABI Platform
prompt_injection_blocker-0.1.5-py3-none-any.whl Python 3 none any Details

Total release size: 27.8 kB

Release files / prompt_injection_blocker-0.1.5.tar.gz

Download URL prompt_injection_blocker-0.1.5.tar.gz
Size 16.3 kB
Tags Source
SHA-256 checksum
How to use checksums
b1f26984670e17781947804a8d93a7b8747e0228017c8bc25674ae6241340eb1
BLAKE2b-256 checksum
How to use checksums
cf77a5894d838588c5085ad3d3bc8bda80b4b3d8dab53b621f02f83d31962bd0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / prompt_injection_blocker-0.1.5-py3-none-any.whl

Download URL prompt_injection_blocker-0.1.5-py3-none-any.whl
Size 11.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a172ff0e2f671af72df9acf7cc96c64734bf7b899eaa8cb5442f5a634c4435b2
BLAKE2b-256 checksum
How to use checksums
be284a6c9ddc36f19eea0751e58f3943a12c00515bbf1ea9422b30329afaa585
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.5 This release

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page