No sign-up11,173 open-source and SaaS tools, with GitHub stats refreshed every day.

INJECT.md

SaaS

INJECT.md audits LLM apps for prompt injection by running a battery of 46 payloads across five attack classes and returning a scored report.

inject.md
INJECT.md homepage screenshot

About INJECT.md

INJECT.md is a prompt-injection audit for applications that let a model read untrusted content such as web pages, emails, PDFs and tool outputs. Its battery has 46 payloads across five classes: direct override, obfuscation and encoding, indirect injection via ingested content, exfiltration side-channels and agentic tool abuse, and each payload cites the technique behind it.

The scored report gives a resistance score, a per-class breakdown and a verdict for every payload as self-contained HTML plus JSON for pipelines, and results that a string match cannot settle are marked as needing review. The site argues that system prompts cannot stop injection and that structural measures such as quarantining untrusted content hold up, and it provides a sandboxed live demo where you can try to leak a throwaway secret.

An audit of your endpoint is priced at 69 dollars, and 8 of the payloads are free to run. It is aimed at teams shipping LLM features that read external content and want a measurable baseline for how well their architecture resists injection.

Key features

  • 46 prompt injection payloads in five classes
  • Scored resistance report with per-class breakdown
  • HTML report plus JSON for pipelines
  • Needs-review flags for unclear results
  • Free subset of 8 payloads
  • Sandboxed attack demonstration

Good fit for

  • Testing an AI assistant that reads email or web pages
  • Giving a security lead a scored injection report
Tags
prompt-injection
llm-security
owasp
ai-security
audit
testing

INJECT.md: questions and answers

What is INJECT.md used for?
INJECT.md audits LLM apps for prompt injection by running a battery of 46 payloads across five attack classes and returning a scored report. It is a good fit for testing an AI assistant that reads email or web pages and giving a security lead a scored injection report.
Is INJECT.md free?
Yes. INJECT.md has a free plan, and paid plans start at $39 per month.
Is INJECT.md open source?
No. INJECT.md is proprietary (closed-source) software and can't be self-hosted. In the Security category, open-source options include ModSecurity, DefectDojo and CISO Assistant.
What are some alternatives to INJECT.md?
Other SaaS products in the Security category include Agnostics, aipwn and 42Crunch.

Open-source alternatives to INJECT.md

See all

SaaS alternatives to INJECT.md

See all