Skip to main content

npm package · live · 2026-10

part of foxmate

foxshield

find hidden text and prompt injection before an agent reads a page

the problem

a web page can hide text that tells an ai agent what to do. the agent reads it and the person never sees it.

what i built

foxshield scans a page for hidden text and prompt injection. its sanitize step drops the hidden text and marks flagged text as untrusted data. a CLI fails a build when a page carries hidden instructions.