uncloak · altaysec
Reveal the prompt injection you can't see.
Paste an AI agent extension — an Agent Skill, an MCP config, or a
rules file (.cursorrules, CLAUDE.md). uncloak decodes the
invisible Unicode and flags injection, exfiltration and supply-chain risks the way the model
reads them — not the way your eyes do.
Runs entirely in your browser. Nothing you paste ever leaves this page.