uncloak · altaysec

Reveal the prompt injection you can't see.

Paste an AI agent extension — an Agent Skill, an MCP config, or a rules file (.cursorrules, CLAUDE.md). uncloak decodes the invisible Unicode and flags injection, exfiltration and supply-chain risks the way the model reads them — not the way your eyes do.

Runs entirely in your browser. Nothing you paste ever leaves this page.