Hidden Unicode / AI Prompt Scanner
Scan text live for invisible Unicode characters — the Unicode Tags block and bidi overrides are flagged High risk (the exact categories documented in real AI agent prompt-injection research), while common zero-width, NBSP, and BOM characters are flagged Low.
How it works
- Paste text, a prompt, or an AI agent skill file
- Every hidden or unusual character is listed live below — name, code point, position, and risk level
- A clean copy with every flagged character removed is ready to copy instantly
Frequently asked questions
Are these characters actually dangerous?
Categories flagged High — the Unicode Tags block and bidirectional override characters — have been documented in 2026 security research (Cloud Security Alliance) as real injection vectors hidden inside AI agent skill files, tool descriptions, and MCP server metadata: invisible in every standard UI, but processed by the underlying model. Low-risk characters are usually just accidental artifacts from copy-pasting.
Does it scan as I type?
Yes — no button to click.
Is my text sent anywhere?
No, everything runs in your browser and nothing is uploaded.
Related tools
From the blog
Update history
- 2026-08-30 Added: a cover image — used as the card thumbnail, social share image, and blog title image.
- 2026-08-30 Fixed: the High/Low risk border colors on flagged characters weren't rendering (a CSS scoping issue affecting dynamically-generated content) — now shows correctly.
- 2026-08-30 Launched: live scan for invisible/suspicious Unicode characters (no button), High/Low risk classification (Unicode Tags block and bidi overrides flagged High — the categories documented in real AI agent prompt-injection research — vs. common zero-width/NBSP/BOM flagged Low), one-click clean text.