PROMPT INJECTION CHECK · LEARN

How to review findings

A scan result is most useful when findings, coverage and the original content are reviewed together.

1. Review the finding

Start with the reported location, excerpt and reason. Compare the finding with the surrounding content and the original file before deciding what it means.

2. Check coverage

Coverage explains what the scanner was able to inspect. A result with no findings is different from a result where relevant content was only partly inspected or unavailable.

3. Consider context

Instruction-like text can be legitimate in documentation, examples, templates or security material. A scanner cannot reliably determine the author's intent from a pattern alone.

4. Decide how the content will be used

Consider what AI system will receive the content and what permissions or tools it has. Higher-impact workflows deserve more careful review and tighter permissions.

5. Keep the limitations in mind

Prompt injection detection is heuristic by nature. Previously unseen or obfuscated techniques may be missed, and benign content may occasionally be flagged. Results support review; they are not a security guarantee.