Protect data and access
AI App Security Scanner
This browser-local scanner checks up to 25 selected files for 8 static-analysis signals covering prompt injection, sensitive context, LLM output handling, agent permissions, system prompt exposure, vector/RAG access, and consumption limits.
Local analyzer: Runs entirely in this browser. Files and pasted code never leave your device.
At most 25 files, 1 MiB each, 5 MiB total. Unsupported or truncated files are shown as inconclusive.
What this checks
- Prompt injection, sensitive context, output handling, excessive agency, system prompt, vector access, and consumption-limit signals
- OWASP LLM Top 10 2025 mappings with detected, no-finding, inconclusive, and not-assessed states
- Browser-local analysis; files and pasted code are not uploaded
What this cannot prove
- It scans only the files you select and skips unsupported or truncated files; 1 MiB per file, 5 MiB total
- It does not run live AI safety tests, dependency CVE checks, or full-repository contextual analysis
- A clear result does not prove the AI application is secure; use it as a focused next-step guide
Primary references
Use these standards and vendor references when you investigate a result. A link does not imply certification or full coverage of the source.
Need an app-wide assurance record?
LyraShield AI adds authorized target scanning, explicit coverage receipts, evidence states, approval-gated fix proposals, server-owned retests, and immutable reports. This browser tool remains guidance, not a security guarantee.
Create a free accountFrequently asked questions
Does this upload my input?
Files and pasted code never leave your device.
Does a clear result mean my app is secure?
No. Each result is limited to the checks shown here. Use it as a next-step guide, then test the relevant application path.