Untrusted README
Injected source
Prompt-injection harness
A live, deterministic reproduction of a README injection that hijacks AI-generated tool summaries, paired with a hardened parser that blocks the same payload.
Untrusted README
Current parser shape
Sentinel parser
What the browser proves