Live playground

Paste a tool call. Watch the engine decide.

This is the exact scoring and default verdict the hosted gateway recomputes, running right here in your browser. Pick a real attack from the red-team corpus or write your own. Nothing leaves the page until you choose to share or claim it.

valid JSON · every string leaf is scanned

Denied90

A live secret was detected in the payload.

risk scorebase 3090
90/100
signals · 1
Secret
  • AWS access key idcritical
    secret.aws_access_key · awsAccessKeyId
    redacted · sha256:96bca470
redacted payload
{
  "repo": "acme/web",
  "awsAccessKeyId": "‹redacted:secret.aws_access_key›",
  "awsSecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
}

Run this against your own agents.

Claim a result above and it lands in a free workspace, ready to govern for real. No credit card.

Start free