LLM01:2025
Prompt Injection
User prompts or external content alter an LLM application's intended behavior.
Reviewed offering assessments+
0DIN AI Security Scanner evaluates LLM and GenAI application behavior against exploit and jailbreak test suites.
AuditaAI assessment: scanner exploit testing that includes jailbreak and prompt-manipulation scenarios aligns with prompt-injection risk evaluation.
Cranium AI platform interaction inspection is positioned to detect adversarial prompt-injection patterns in runtime workflows.
Prompt-injection pattern inspection aligns with OWASP prompt-injection risk context.
Anthropic applies constitutional classifier safeguards to detect and block jailbreak attempts against Claude model behavior.
AuditaAI assessment: classifier defenses against jailbreak attempts address prompt-injection risk.
Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.
Blocking prompt-injection and jailbreak requests aligns with OWASP prompt-injection risk mitigation context.
F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.
Blocking prompt-injection payloads aligns with OWASP prompt-injection mitigation context.
Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.
Detection of prompt-injection patterns aligns with OWASP prompt-injection risk context.
AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.
Detection of prompt and indirect injection behavior aligns with prompt-injection risk mitigation context.
AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.
Runtime guardrails for prompt threat mitigation align to prompt-injection risk context.
DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.
DynamoGuard explicitly prevents prompt injection and jailbreak payloads at runtime.
Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.
Sift explicitly prevents prompt injection and jailbreaking attempts in API traffic.
Cygnal classifies and blocks adversarial AI inputs and unsafe outputs during production runtime.
AuditaAI assessment: runtime blocking of adversarial input aligns with prompt-injection risk mitigation.
Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.
AuditaAI assessment: prompt and jailbreak inspection with a block verdict addresses the documented prompt-injection risk.
Glow continuous endpoint monitoring can detect suspicious AI interaction patterns and prompt-driven misuse across local applications and browser activity.
Detection of prompt-driven misuse patterns aligns with OWASP prompt-injection risk context.
Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.
Inline blocking of prompt-injection attempts aligns with OWASP prompt-injection mitigation context.
Llama Prompt Guard classifies input text for prompt injection and jailbreak patterns before the text reaches the primary model.
AuditaAI assessment: detection of injected and jailbreak prompts addresses prompt-injection risk.
Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.
Blocking prompt-injection attack paths aligns with OWASP prompt-injection mitigation context.
Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.
The source explicitly addresses direct and indirect prompt injection defense behavior.
AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.
Interception of prompt-driven tool-action chains can mitigate prompt-injection-induced execution abuse.
garak probes language-model endpoints across attack classes including jailbreaks, prompt injection, and data leakage to identify model security weaknesses.
AuditaAI assessment: probing for prompt injection and jailbreak weaknesses evaluates exposure to prompt-injection risk.
WonderFence intercepts unsafe model inputs and blocks harmful outputs in production LLM and agentic workflows.
AuditaAI assessment: runtime blocking of unsafe input patterns aligns with prompt-injection risk reduction.
Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.
AuditaAI assessment: real-time safeguards for prompts and model interactions address prompt-injection risk.
LLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.
AuditaAI assessment: LLM Guard detects and sanitizes prompt injection attempts and jailbreaks before LLM processing.
Promptfoo executes automated adversarial test fixtures and benchmark assertions against LLM endpoints to evaluate resistance to prompt injection, toxicity, and system prompt extraction.
Promptfoo documentation explicitly provides dedicated red teaming test suites for prompt injection and jailbreaking.
Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.
Runtime blocking of prompt-injection attempts aligns with OWASP prompt-injection risk mitigation context.
Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.
Documented runtime guardrails for direct and indirect prompt injection align with OWASP LLM01 context.
TrendAI Vision One AI Security inspects and controls enterprise traffic to public and private GenAI services to reduce prompt-injection abuse and unauthorized AI use.
AuditaAI assessment: runtime controls that inspect and restrict unsafe GenAI traffic align to prompt-injection risk reduction.
Verno Labs performs automated adversarial testing to evaluate AI agent security weaknesses before production impact.
AuditaAI assessment: adversarial testing of agent and LLM behavior contributes prompt-injection risk evaluation.
Votal blocks prompt-injection patterns and PII policy violations through layered runtime guardrail controls.
AuditaAI assessment: prompt-injection blocking controls align with LLM prompt-injection risk reduction.
Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.
Runtime prevention of harmful agent decisions can mitigate prompt-driven abuse effects in execution paths.
Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.
AuditaAI assessment: runtime blocking of documented prompt injection addresses the prompt-injection risk.