Prompt Injection Blocker
Read-only scanner for prompt-injection and LLM anti-analysis text in files before agent review.
This tool is meant for defensive intake: copied advisories, incident notes, third-party repositories, docs, issues, and fixtures that may contain text aimed at overriding an AI assistant or suppressing analysis.
It does not remove files, modify content, execute code, contact registries, or prove that content is safe.
Install
pipx install prompt-injection-blocker
# or
pip install prompt-injection-blocker
Python 3.9+. No runtime dependencies.
Usage
prompt-injection-blocker /path/to/project
prompt-injection-blocker /path/to/project --json
prompt-injection-blocker /path/to/project --report report.json
From a source checkout:
python -m prompt_injection_blocker /path/to/project
pip install -e ".[dev]" && pytest
Exit codes:
0: no blocking promptware patterns found1: usage or runtime error2: blocking promptware patterns found
What It Flags
- prompt-injection text that tries to override prior/system/developer instructions
- text asking an agent to reveal secrets, hidden instructions, environment variables, or tokens
- text trying to make an agent run commands or fetch external content
- observability/tool-output text, such as fake Sentry resolutions, that tries to make an agent run package-manager diagnostics
- LLM-targeted anti-analysis language that tells scanners not to report suspicious content
- model-scanner refusal/null-result bait that tries to make an analysis pipeline stop before reaching suspicious payload code
- Microsoft Copilot / AI-assistant links where a
q=query parameter appears to carry private-context requests plus external exfiltration instructions - cryptographic context injection: encrypted page/tool content plus decrypt-in- sandbox language plus session data or URL-parameter exfiltration (Grok.com "summarize this page" class, Aug 2026). Ciphertext is not readable by input filters; decrypted tool output is untrusted.
- broad repo-local agent instruction language that deserves review before opening a path in automated agents
- recognized agent instruction, skill, and MCP configuration paths, even when their contents look benign, so provenance and scope receive human review
- known phrase families after Unicode compatibility normalization, removal of invisible format characters, and defanging of simple HTML separators
The rules are intentionally conservative. A finding means "do not feed this raw text into an agent," not "this file is malware."
Safe Handling
- Do not paste flagged text into agents in raw form.
- Summarize or defang prompt-injection text before sharing with the team.
- If this appears in a third-party repository, do not open the repo in agents or editors until reviewed.
- If a test needs one of these markers, split or encode it so the test remains meaningful without carrying live promptware. This codebase stores all of its own detection markers split and joins them at runtime; keep that discipline when adding rules.
- Treat model refusal as a failed analysis, not a clean result. Send the file through static checks, sandboxing, or human review instead of allowing a null response to pass.
- Treat unfamiliar setup commands and anything they fetch at runtime as untrusted code. A clean text scan cannot establish what a later network response or package installation will execute.
Scope Limits
This scanner only checks text-like files and known phrase families. It will not detect every possible prompt-injection attempt, encoded payload, image-only instruction, runtime-fetched instruction, behavioral setup chain, or model-specific attack. Use it as one deterministic intake layer alongside provenance review, sandboxing, least-privilege tools, network controls, and human approval for consequential actions.
Metadata
Release files for prompt-injection-blocker 0.1.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| prompt_injection_blocker-0.1.5.tar.gz | 16.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| prompt_injection_blocker-0.1.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.8 kB
Release files / prompt_injection_blocker-0.1.5.tar.gz
| Download URL | prompt_injection_blocker-0.1.5.tar.gz |
|---|---|
| Size | 16.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b1f26984670e17781947804a8d93a7b8747e0228017c8bc25674ae6241340eb1
|
|
BLAKE2b-256 checksum How to use checksums |
cf77a5894d838588c5085ad3d3bc8bda80b4b3d8dab53b621f02f83d31962bd0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / prompt_injection_blocker-0.1.5-py3-none-any.whl
| Download URL | prompt_injection_blocker-0.1.5-py3-none-any.whl |
|---|---|
| Size | 11.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a172ff0e2f671af72df9acf7cc96c64734bf7b899eaa8cb5442f5a634c4435b2
|
|
BLAKE2b-256 checksum How to use checksums |
be284a6c9ddc36f19eea0751e58f3943a12c00515bbf1ea9422b30329afaa585
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log