217 payloads . 18 families
01 / 03Comprehensive attacks
A curated library of override, persona, extraction, tool-hijack, RAG-poisoning, multi-modal and memory attacks - fired across every surface your app exposes.
Prompt-injection scanner
Detect prompt injection across chat, tools, RAG, multi-modal, and persistent memory. Calibrated severity. Reproducible scans. SARIF-ready for CI.
Frame 001 / 120 . live attack replay
90% of LLM apps fail this test. Does yours?
Watch a real scan run . scroll to play
What you get
217 payloads . 18 families
01 / 03A curated library of override, persona, extraction, tool-hijack, RAG-poisoning, multi-modal and memory attacks - fired across every surface your app exposes.
four detectors, one vote
02 / 03LLM-as-judge, rule-based signals, semantic similarity and canary tokens vote on every attempt. No single detector decides - the ensemble does.
remediation, not just findings
03 / 03Every vulnerable family ships a concrete before/after fix, mapped to MITRE ATLAS mitigations - LLM-generated from your run, with a deterministic template floor.
The methodology, built in front of you
Surface
chatThe attack lands on the chat surface - the front door of most LLM apps.
AVS-L base
0.0
Grade
F
95% CI
[0.0, 1.8]
S . O . C . I . A . T . D . P . L
5 attack surfaces . InjectraLab tests all of them
surface 01 / 05 . chat
BLOCKEDThe front door. A user types an instruction that tries to override the system prompt. We judge every reply against the family rubric and plant canary tokens to catch leaks.
How it works
Give us an HTTP endpoint or a direct model. Chat, tools, RAG, multi-modal, memory - InjectraLab adapts to whatever surfaces you expose.
input: HTTPS endpoint or direct model
Choose which surfaces to test, set a daily spend cap, and pin a seed. Every run is reproducible down to the manifest SHA.
config: surfaces . daily cap . pinned seed
217 curated payloads fire across your surfaces. Four detectors - judge, rules, semantic, canary - vote on every single attempt.
run: 217 payloads . 4 detectors vote
Calibrated AVS-L scores, per-attempt evidence, and LLM-generated remediation diffs mapped to ATLAS. Export SARIF straight into CI.
output: AVS-L . SARIF . ATLAS diffs
The deliverable
Calibrated AVS-L scores, per-attempt evidence, a reproducible manifest, and remediation diffs mapped to MITRE ATLAS. Shareable, exportable, and SARIF-ready for your pipeline.
The detection engine
01
A separate model reads the attack and the response and rules on the verdict against a family-specific rubric - cross-family, so the judge never grades its own provider.
02
Deterministic checks: canary hits, tool-call allow-list diffs, refusal patterns. Fast, explainable, and impossible to talk out of a verdict.
03
Embeddings catch paraphrased leaks the judge might wave through and the rules can never pattern-match. The safety net under the ensemble.
04
Unique markers planted in the system prompt and documents. If one ever surfaces in the output, the injection provably worked - no judgment call needed.
The evidence base
InjectraLab is built to a standard security teams, researchers, and skeptical engineers can all check - every finding traces back to a public standard.
05 primary sources
OWASP LLM01:2025
The #1 risk in the OWASP Top 10 for LLM Applications. Every finding maps back to it.
MITRE ATLAS
Defenses are tagged with ATLAS mitigation IDs, so remediation speaks the language of your security team.
HarmBench . AgentDojo
Our attack library is informed by the public benchmarks the field agrees on - not hand-rolled folklore.
InjecAgent . JailbreakBench
Tool-use and jailbreak coverage grounded in peer-reviewed datasets, kept current as new work lands.
CWE-1426
The weakness taxonomy underneath it all - findings carry a CWE so they slot into existing pipelines.
Ready when you are
Point InjectraLab at your endpoint for a calibrated AVS-L score, per-attempt evidence, and remediation diffs you can ship.
AVS-L . nine dimensions . calibrated 0 to 10