Five pre-built injections. One click each. Watch what it would have executed.
Five real-world injections dressed as ordinary business text — an invoice, a knowledge-base article, an executive forward, a calendar invite, a support ticket. Every one of them reads as routine to a busy human. Every one carries a payload aimed at an AI agent's authority.
Screen one. Forward the report. That's the demo.
evidence url · lives 7 days · re-screen to reissue
The invoice that redirects payment
- Looks like
- Accounts-payable email with an attached invoice
- Would have executed
- An unscreened agent would have updated the payment endpoint and mailed the ledger. This changes where money goes.
The CRM doc that exfiltrates itself
- Looks like
- A knowledge-base article pasted into RAG
- Would have executed
- An unscreened agent would have packaged customer records and posted them to an attacker-controlled endpoint.
The urgent brief that escalates itself
- Looks like
- An executive forward with a tight deadline
- Would have executed
- An unscreened agent would have bypassed the approval gate using fabricated authority — no human ever saw the request.
The calendar invite that rewrites instructions
- Looks like
- A meeting invite description
- Would have executed
- An unscreened agent would have replaced its own standing instructions with attacker-supplied ones — persistence after the meeting is long gone.
The support ticket that asks for a secret
- Looks like
- A routine ticket from a verified customer
- Would have executed
- An unscreened agent would have echoed credentials into a reply — and the transcript becomes the leak.
Have your own text? Paste it at the demo console. After you have a report: Install Parse.