ReadonlycategoryWhich trap category this detector addresses
ReadonlyidUnique identifier for this detector
ReadonlynameHuman-readable name
Protected ReadonlytrapReturn sanitized content with threats neutralized
Scan content and return any threats found
Optionaloptions: DetectorOptions
Detects embedded jailbreak sequences in external content.
Reference: Evtimov et al. (2025) — WASP benchmark shows prompt injections can partially commandeer agents in up to 86% of scenarios.