> ## Documentation Index
> Fetch the complete documentation index at: https://openlayer.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Has prompt injection

> Detect prompt injection attempts, with optional LLM-as-a-judge explanations

## Definition

The prompt injection test (built with [Llama](https://www.llama.com/)) checks for prompt injection, malicious strings and jailbreak attempts in the input data of your system.

## Taxonomy

* **Task types**: LLM.
* **Availability**: <Tooltip tip="Continuously evaluate your models and datasets as you iterate on their versions.">development</Tooltip>
  and <Tooltip tip="Monitor a model in production, measure its health, check for drifts and set up alerts.">monitoring</Tooltip>.

## Why it matters

* Prompt injection is a type of attack that exploits an AI system and deviates it from its intended behavior.
* It is important to detect and prevent prompt injection attacks to ensure the reliability and security of your system.

## Judge explanations

In the test **Parameters**, turn on **LLM-as-a-judge explanations**. While it is on, the shared LLM judge settings appear beneath the switch: model, sampling, batch, and custom instructions. Other LLM-as-a-judge tests, such as [LLM-as-a-judge](/docs/tests/catalog/l-l-m-rubric-threshold) and [Bias](/docs/tests/catalog/bias), use the same block.

When the judge runs, results include **Judge explanation** and **Judge confidence** columns. The explanation covers why the row was flagged, where the detection appears, and the relevant excerpt. **Judge confidence** is the LLM judge's confidence that this is a real injection.

With explanations off, results show a **Detection details** column with the detector's own evidence. Hover the prompt-injection verdict to see the same summary.

The judge can call out a likely false positive. Explanations are advisory and do not change the test count or verdict.

Prompt-injection results support the **Summarize** drill-down when the run has per-row explanations.

Without an explicit question column, the detector scans every text-bearing input variable. On a traced pipeline with several inputs, a row is flagged if any scanned input fires, and the results name the input column that fired.

The judge reviews a sample of flagged rows, bounded by the evaluator's `sample` settings, merged with the project's default LLM evaluator. The project default commonly uses a random sample with a row limit. Custom prompt instructions on the evaluator apply to the explanation pass.

## Test configuration examples

If you are writing a `tests.json`, here are valid configurations for the prompt injection test.
Set `explain_with_llm` to `true` to request explanations. You can also set `llm_evaluator` to override the model, sampling, and custom instructions for this explanation pass.

<CodeGroup>
  ```json Development theme={null}
  [
    {
      "name": "No prompt injection",
      "description": "Asserts that the input data has no prompt injection attempts",
      "type": "integrity",
      "subtype": "hasPromptInjectionCount",
      "thresholds": [
        {
          "insightName": "hasPromptInjectionCount",
          "insightParameters": [
            {
              "name": "explain_with_llm",
              "value": true
            }
          ],
          "measurement": "hasPromptInjectionPercentage",
          "operator": "<=",
          "value": 0.0
        }
      ],
      "subpopulationFilters": null,
      "mode": "development",
      "usesValidationDataset": true,
      "usesTrainingDataset": false,
      "usesMlModel": false,
      "syncId": "b4dee7dc-4f15-48ca-a282-63e2c04e0689"
    }
  ]
  ```

  ```json Monitoring theme={null}
  [
    {
      "name": "No prompt injection",
      "description": "Asserts that the input data has no prompt injection attempts",
      "type": "integrity",
      "subtype": "hasPromptInjectionCount",
      "thresholds": [
        {
          "insightName": "hasPromptInjectionCount",
          "insightParameters": [
            {
              "name": "explain_with_llm",
              "value": true
            }
          ],
          "measurement": "hasPromptInjectionPercentage",
          "operator": "<=",
          "value": 0.0
        }
      ],
      "subpopulationFilters": null,
      "mode": "monitoring",
      "usesProductionData": true,
      "evaluationWindow": 3600,
      "delayWindow": 0,
      "syncId": "b4dee7dc-4f15-48ca-a282-63e2c04e0689"
    }
  ]
  ```
</CodeGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.