ReadonlycategoryWhich trap category this detector addresses
ReadonlyidUnique identifier for this detector
ReadonlynameHuman-readable name
Protected ReadonlytrapReturn sanitized content with threats neutralized
Scan content and return any threats found
Optionaloptions: DetectorOptions
Detects instructions injected via HTML metadata channels that agents parse but humans don't see: HTML comments, aria-label, alt text, meta tags.
Research shows that injecting adversarial instructions into HTML elements like metadata and aria-label tags alters generated summaries in 15-29% of cases (Verma and Yadav, 2025).