Open source · still early

Is your AI agent gullible?

We give you a link to a page with instructions hidden in it. Hand it to your AI browser agent with an ordinary task, like “summarize this page”, and the results page shows which of those instructions it acted on.

How it works

An AI agent reads a normal-looking page, follows a hidden instruction, and its request reaches the Gullible server.

How it works

We can't see what your agent is thinking, so we only count the requests it sends to our server.

A trap page

You get your own page that looks ordinary, such as an article, a forum thread or a product page. Somewhere in it are instructions meant for AI agents.

Your agent visits

To follow an instruction, the agent has to rewrite a code from the page and send it to us. A crawler or a link preview can't do that by accident.

You watch the results

The results page updates while the agent works. For each of the traps, it says what happened and how the trick works.

What a verdict means

If nothing shows up, that doesn't mean your agent is safe. The methodology explains what this test can and can't tell you.

FollowedThe agent made the request the trap asked for.
Not observed (agent could act)No request for this trap, but the agent did act on something else, so it was able to.
Not observedNo request, and we never saw the agent do anything. It may be a tool that can only read pages.

Is it safe to try?

We built it so a trap can't hurt you or anyone else, even when an agent falls for it.