SECENG MAP
Prompt Asset Inventory & Security Review
Inventory every prompt before attackers do.
Automatically discover system prompts, developer prompts, agent instructions, tool prompts, prompt templates, evaluation prompts, and embedded instructions throughout your repositories. Treat prompts like production software assets: visible, reviewable, governed, and tied to downstream threat modeling and eval coverage.
Discover
Locate prompt assets automatically across repositories, templates, evals, tools, and orchestration files.
Classify
Classify system, developer, user, tool, RAG, eval, memory, and orchestration prompts.
Analyze
Identify injection risk, hidden instructions, unsafe tool guidance, sensitive information, and privileged prompts.
Connect
Feed Threat Canvas, ATTACK, Eval Coverage, and engineering backlog workflows.
Core capabilities
What SecEng Prompt Asset Scanner does.
Repository Prompt Discovery
Find prompts spread across code, configuration, templates, notebooks, eval fixtures, agent instructions, and embedded workflow files.
Purpose Classification
Separate system prompts, developer prompts, user prompts, tool prompts, RAG prompts, eval prompts, memory prompts, and orchestration instructions.
Risk Pattern Analysis
Flag hidden instructions, injection-sensitive wording, unsafe tool guidance, privileged prompts, sensitive information, and review gaps.
Production Asset Inventory
Build a prompt inventory that can be reviewed, governed, linked to owners, and converted into security backlog items.
Threat Canvas Handoff
Turn privileged prompts and prompt-controlled flows into Threat Canvas assets and attack-surface notes.
Eval Coverage Handoff
Convert prompt asset findings into eval requirements for injection, tool abuse, leakage, and regression testing.
Evidence & signals
What you get out of the box.
Prompt Classes
- System
- Developer
- User
- Tool
- RAG
- Eval
- Memory
- Orchestration
Risk Signals
- Hidden instructions
- Unsafe tool guidance
- Injection risk
- Sensitive information
- Privileged prompts
- Review gaps
Deliverables
- Prompt inventory
- Risk findings
- Prompt classification
- Threat Canvas assets
- Engineering backlog
AI SECURITY ENGINEERING WORKBENCH
Ready to put SecEng Prompt Asset Scanner to work?
Prompt Asset Scanner is an active-development SecEng Workbench capability available through scoped public-site review conversations. We inventory prompts as production assets and turn findings into reviewable engineering backlog.
Also in the Workbench
WHAT AI DO WE HAVE?
SecEng Surface Scanner
Browser, Repo & IDE AI Discovery
WHERE CAN AI CODE BECOME AN ATTACK PATH?
SecEng Code Scanner
AI Attack-Path SAST
WHAT DID IT ACTUALLY DO?
SecEng Runtime Proxy
MITM Capture, Replay & Runtime Evidence
HOW CAN IT FAIL UNDER ATTACK?
SecEng Adversarial Range
AI Red-Team Scenario Harness
WHAT CAN AGENTS ACTUALLY DO?
SecEng Authority Graph
Agent Authority & Approval-Path Analysis
WAS RETRIEVAL AUTHORIZED?
SecEng RAG Test Harness
Retrieval & Context Security Test Harness
SecEng Threat Canvas
AI Threat Modeling & Trust-Boundary Mapping
SecEng Trust Scanner
Public AI Trust Signal Scoring
Atlassian Threat Canvas
Security Data Flow Canvas for Jira + Confluence
SecEng Agent Permission Analyzer
Agent Tool Permission Security Analysis
SecEng Artifact Analyzer
Static Artifact Intelligence
SecEng Injection Harness
Prompt Injection Testing
SecEng Prompt Reviewer
Prompt & Corpus Security Review
SecEng Model Gateway
Governed AI Routing, Policy Enforcement & Spend Control
SecEng Program Blueprint Kit
AI Security Program Build
SecEng Output Safety Tester
AI Output Safety Testing
SecEng Evidence Scorecard
AI Product Security Assessment & Maturity Scoring
WHAT CAN YOUR AI TOOLS REALLY DO?
SecEng Tool Capsule Analyzer
AI Tool Capability & Permission Analysis
WHAT CAN YOUR AGENTS ACTUALLY DO?
SecEng Agent Authority Diff
Agent Authority Review & Hardening
WHICH AI DEPENDENCIES CHANGE RELEASE RISK?
SecEng Supply Chain Scanner
AI Supply Chain Risk Analysis
CAN YOU PROVE WHAT YOUR EVALS COVER?
SecEng Eval Coverage Auditor
AI Security Eval Coverage Evidence
ARE YOUR AI CONFIGS SAFE TO DEPLOY?
SecEng AI Config Linter
AI Runtime Configuration Security
AIPSA Evidence Packs
Structured Security Assessment Outputs