Several browser entry points
Hidden-page observations, text paste, copying, manual scans, images, and supported conversation views feed shared analysis functions.
Browser extension prototype
Inspect suspicious instructions before they blend into a workflow.
A Chrome extension prototype that combines local text heuristics with Gemini classification to flag potential prompt injection. It connects hidden-DOM scanning, clipboard handling, image transcription, and conversation monitoring to visible review and remediation controls.
Instructions can arrive inside a webpage, copied text, an image, or a conversation. A browser-side inspection layer makes the source, suspected spans, and proposed handling visible at the point where a user encounters the content.
Hidden-page observations, text paste, copying, manual scans, images, and supported conversation views feed shared analysis functions.
Local Unicode, keyword, imperative, and encoding signals are combined with structured Gemini output. The confirmation rule and severity thresholds are explicit in source.
Character spans are merged, bounded, and augmented before display or removal. Page highlighting and paste insertion have separate policies.
The primary image flow transcribes first, then classifies the extracted text. A combined vision path handles specified fallbacks and suspected visual-only content.
Several browser event sources feed one shared pipeline. Model confidence and local suspicion are separate signals.
Adjust simulated model confidence, the configured threshold, and local instruction suspicion. The example assumes the model flagged an injection so the two confirmation paths are visible.
Simulated inputs only. No page, clipboard, image, or model API is accessed. A flagged example is a review signal, not an established security finding.
Threat records retain original text, optional decoded text, suspected spans, confidence, and rationale. Review surfaces make those signals visible instead of exposing only a badge.
Live DOM content is highlighted in non-BLOCK modes. Clipboard surgical mode can remove spans but falls back to highlighting the original if every character would be removed.
Local heuristics run in the extension, while semantic and vision classification use Gemini. No separate application backend does not mean all analysis is offline.
Implementation details, examples, and project documentation.
Inspected OCR-to-text flow, model-call gating, confirmation rule, span reconciliation, and persistence.
Inspected highlight-first page behavior, media handling, and BLOCK replacement.
Inspected surgical removal, highlight/block modes, and full-removal fallback.
Architecture and descriptions reflect the linked repository snapshot. The playground explains a mechanism; it does not execute the repository or report measured performance.