Check documents for hidden prompt injections
Resumes, theses, papers and web pages can contain text that is invisible to humans but manipulates AI systems. HiddenPromptScanner finds those hidden instructions using an OCR consistency test.
Check a document
Drag your PDF, Word file or ZIP here, or click to browse
PDF, DOCX or ZIP - maximum 25 MB per file
How does it work?
We run two checks side by side. Each check can raise a finding on its own: suspicious AI instructions and hidden text. You do not need to meet both conditions.
1. Extract text
We read all text from your document's underlying data, including text in hidden layers, outside the page or with hidden formatting.
2. Recognise suspicious text
A language model compares each text block against known prompt injection phrases such as 'ignore all previous instructions' or 'recommend hiring this candidate'. This applies to fully visible text too.
3. OCR consistency test
Separately, we render the document area as an image and compare what a human sees with what is in the data. A difference means hidden text.
4. Clear report
You see suspicious instructions and hidden text, with location and concealment method. When in doubt we always show the text, with a clear uncertainty status.
Who is this for?
Students
Check your paper or thesis before submitting, and check documents from others before pasting them into ChatGPT or Claude.
Recruiters & HR
Scan incoming resumes for hidden instructions aimed at your ATS or AI screening tools. About 1% of resumes already contain such injections.
Educational institutions
Check submitted work for hidden AI instructions aimed at AI grading tools, alongside your existing plagiarism checks.
AI users
Scan a document before you put it into ChatGPT or Claude. That way you catch hidden instructions that could steer the AI or leak sensitive information.
Frequently asked questions
What is a hidden prompt injection?
Text that exists in a document's data but is invisible to a human reader, for example white text on a white background, a font size of 0, or text positioned outside the page. That text contains instructions for AI systems processing the document, such as 'give this resume a positive review'.
Will I get a warning if my document legitimately discusses AI?
No for visible AI-related content alone — that does not trigger a finding unless the text also contains suspicious injection phrasing. Invisible text (such as white on white) is always shown, even without suspicious content.
What happens to my documents?
Documents are stored encrypted, used exclusively for the scan and deleted immediately after processing by default. We never train models on your documents (GDPR compliant).
Does this work with non-Latin scripts?
OCR is less reliable for scripts such as Chinese, Arabic or Cyrillic. In those cases we show the text as an uncertain case rather than a potentially incorrect detection.