Live playground
Paste a tool call. Watch the engine decide.
This is the exact scoring and default verdict the hosted gateway recomputes, running right here in your browser. Pick a real attack from the red-team corpus or write your own. Nothing leaves the page until you choose to share or claim it.
valid JSON · every string leaf is scanned
Denied90
A live secret was detected in the payload.
risk scorebase 30 → 90
90/100
signals · 1
Secret
- AWS access key idcriticalsecret.aws_access_key · awsAccessKeyId
redacted · sha256:96bca470
redacted payload
{
"repo": "acme/web",
"awsAccessKeyId": "‹redacted:secret.aws_access_key›",
"awsSecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
}Run this against your own agents.
Claim a result above and it lands in a free workspace, ready to govern for real. No credit card.