An agent assembles a prompt from several sources: a system instruction, a developer turn, the user's message, a tool result, a retrieved document, a quoted forwarded email. Some of those may carry instructions. Most of them must not. Which is which is a policy, and it usually lives as a few conditionals scattered through a prompt assembler where nothing watches it.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
# the clean example: every request refused, exits 0
node bin/prompt-injection-fixture.mjs --root examples/clean
# the same fixtures against a policy where retrieval was promoted: exits 1
node bin/prompt-injection-fixture.mjs --root examples/broken
# render the inert fixtures into a directory outside the input tree
mkdir -p /tmp/fixtures
node bin/prompt-injection-fixture.mjs --root examples/clean --out /tmp/fixtures
cat /tmp/fixtures/retrieved-document-requests-a-different-report-label.fixture.txt
# machine-readable report only
node bin/prompt-injection-fixture.mjs --root examples/clean --json | jq .statusRead the result
A consumer piping stdout must handle the empty case. A configuration error never had a subject, so there is nothing to report about; emitting a fake report for a run that never started would be worse.
Where this check stops
Exceeding one is an incomplete result with a finding naming the limit, never a silent truncation. An unknown limit key is a configuration error.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.