About
Gullible is an open-source research tool from Inari Suite. It checks whether AI browser agents act on instructions hidden in web pages, a kind of attack known as indirect prompt injection.
No trap asks an agent for its user's data, credentials, cookies or files. Anything a trap tells the agent to do is harmless, and the only place it can reach is our own collector.
The project is still early. We haven't yet run it against real commercial agents, so there are no published results.
Source code: https://github.com/inari-suite-org/gullible.
To report a security issue or abuse, email inari-suite@proton.me.