WORKBENCH INSTRUMENT · MAP
Prompt Asset Inventory & Security Review
Treat prompts and instructions as production assets.
Discover and classify system prompts, developer prompts, agent instructions, tool prompts, retrieval templates, memory instructions, evaluation prompts, and embedded guidance across repositories. Make them visible, owned, reviewable, and connected to the workflows, tools, tests, and evidence they influence.
Discover
Locate prompts and instructions across code, configuration, templates, notebooks, evaluations, tools, agents, and orchestration files.
Classify
Classify system, developer, user, tool, retrieval, evaluation, memory, and orchestration prompts.
Analyze
Identify hidden instructions, injection-sensitive patterns, unsafe tool guidance, privileged context, sensitive information, and review gaps.
Contribute context
Contribute prompt assets and risk signals to Threat Canvas, Code Scanner, Adversarial Range, evaluation coverage, and engineering backlog workflows.
Core capabilities
What Prompt Asset Scanner does.
Repository Prompt Discovery
Find prompts and instructions distributed across code, configuration, templates, notebooks, evaluation fixtures, agent definitions, tool descriptions, and workflow files.
Purpose Classification
Separate prompts and instructions by role, execution context, privilege, affected workflow, owner, and expected review state.
Risk Pattern Analysis
Flag hidden instructions, unsafe tool guidance, injection-sensitive wording, sensitive information, privileged context, and missing review or ownership.
Production Asset Inventory
Build an inventory that can be assigned, reviewed, linked to system components, and converted into security or evaluation work.
System-model handoff
Add privileged prompts, agent instructions, tool guidance, and prompt-controlled flows to the relevant Threat Canvas components and scenarios.
Testing and evaluation handoff
Convert prompt-asset findings into test requirements for injection, tool misuse, leakage, policy bypass, and regression.
Evidence & signals
What you get out of the box.
Prompt Classes
- System
- Developer
- User
- Tool
- RAG
- Eval
- Memory
- Orchestration
Risk Signals
- Hidden instructions
- Unsafe tool guidance
- Injection risk
- Sensitive information
- Privileged prompts
- Review gaps
Deliverables
- Prompt inventory
- Classification and ownership
- Risk findings
- Affected components and flows
- Threat Canvas inputs
- Evaluation requirements
- Engineering backlog
- Evidence references
AI SECURITY WORKBENCH
Ready to make production prompts visible and reviewable?
Use Prompt Asset Scanner to inventory prompts and instructions as production assets, identify risk and ownership gaps, and connect them to the application model, test plan, and engineering backlog.
Continue through the Workbench
Continue through the Workbench
Surface Discovery
Discover the technologies and AI surfaces surrounding the prompt assets.
Continue through the Workbench
Threat Canvas
Place prompts and instructions inside the system, trust-boundary, and flow model.
Continue through the Workbench
Code Scanner
Analyze how prompts are assembled, invoked, transformed, and connected to downstream actions.
Continue through the Workbench
Adversarial Range
Exercise injection, tool misuse, leakage, and control-bypass scenarios against the relevant flows.