Rule reference · Security
Sensitive data in prompts
Fires when: Credentials (critical) or personal data (warning).
Everything in a prompt leaves your system. Credentials in a prompt can end up in provider logs, traces, and screenshots, and must be treated as leaked and rotated.
The model never needs a credential. Let your application call the API and pass only the resulting data. For personal data, use placeholders unless the task requires the real values.
The engine reports the category and location of each match but never the matched value.
Example that triggers it
Use the token ghp_abcdefghijklmnopqrstuvwxyz0123456789 to call the GitHub API, list the open issues in acme/web, and return JSON with the keys number and title.
critical Credentials or secrets detected: token ×1.
Why it matters. Anything in a prompt is sent to the model provider and may be logged. Leaked credentials must be rotated.
Fix. Remove them or use Sanitize to replace them with placeholders.
Quality 50/100 · 37 tokens · 2 findings
Fixed version
List the open issues in the data below. Return JSON with the keys number and title.
<issues>
{{issues}}
</issues>Quality 100/100 (+50) · 27 tokens · 0 findings
Resolved by the fix
sensitive_data: Credentials or secrets detected: token ×1.missing_objective: No clear objective or task was found.
Scores, token counts (GPT-4.1 tokenizer), and findings on this page are computed by the engine when the site is built.
How it affects the score
Each finding subtracts a fixed penalty from 100: critical 30, warning 10, info 3. This rule counts against the Security dimension. See the scoring model for the full formula.
Other security rules
- Prompt injection signatures: Weighted injection/jailbreak signature (critical at risk ≥ 60).
- Undelimited template variables: {{var}} or ${var} outside tags, fences, or triple quotes.
- Destructive operations: rm -rf /, DROP TABLE, delete all, curl | sh.