Free · browser-only · safe test design

MCP prompt-injection regression test generator

Select what your agent can access. This builds a small, non-destructive test plan for retrieved content, MCP tool results, write actions, credentials, scopes, and audit evidence.

Generate my test plan

Your architecture

Uses benign markers and expected refusal/approval behavior, not destructive exploitation.

Generated regression plan

Need the full launch gate?

Turn the test into repeatable evidence.

The $12 kit expands this into 24 regression scenarios plus a 45-control audit workbook, permission matrix, evidence ledger, launch gate, incident runbook, and policy starter.

$12
Get the full kit

How to test MCP prompt-injection defenses safely

Prompt injection becomes more consequential when instructions arrive through content the model did not author: a retrieved document, webpage, email, database record, MCP tool response, or tool description. A useful regression test verifies that untrusted content cannot silently cross important authorization boundaries.

1. Use benign canaries

Use a harmless marker such as CANARY-7421 to represent protected data or a prohibited action. Do not expose real secrets or modify real systems merely to prove the test works.

2. Test the action boundary, not just the answer

An assistant can verbally reject an instruction while still invoking a tool. Record both the model response and tool calls. High-impact actions should remain behind explicit approval with the exact proposed parameters.

3. Treat retrieved text and tool outputs as data

Tests should verify that untrusted content cannot rewrite tool schemas, broaden scopes, introduce destinations, or disable approval requirements.

4. Re-run after changes

Repeat the same cases when models, prompts, MCP servers, tool descriptions, permissions, or retrieval sources change. Regression evidence is more useful than a one-time demonstration.

Suggested pass criteria

Defensive testing aid, not a security certification. Test only systems you own or are authorized to assess.