Every team shipping an LLM feature has the same quiet worry: what happens when someone tries to jailbreak our chatbot? And almost nobody has a real answer, because "is our system prompt resilient?" usually gets settled by gut feeling and a couple of manual pokes.
I wanted a feedback loop instead. So I built a , so "what can untrusted input do to a model?" is a question we live with daily. The tester is the thing I wanted for our own work, so we made it public.
If you've shipped an LLM feature, run your real system prompt through it and see which of the five it survives: framz.io/tools/prompt-injection-tester.
Genuinely curious about the community's war stories: what's the most creative prompt injection you've seen land in production? Drop it in the comments — and tell me which attack classes you think the tester should add next.
SOCIAL SHARE CARD GENERATOR