Security
Compare safe and unsafe PDF extraction runs to detect hidden text, off-page content, tiny text, and hidden-layer prompt injection risks
Call this tool from your code in three languages.
# 1) Request a presigned URL → returns { uploadUrl, storageKey }
curl -X POST 'https://api.elysiatools.com/api/upload/presign/pdf-prompt-injection-scanner' \
-H 'Content-Type: application/json' \
-d '{"filename":"pdfFile.ext","contentType":"application/octet-stream","size":12345}'
# 2) PUT the file bytes directly to the presigned uploadUrl
curl -X PUT '<presigned uploadUrl>' \
--data-binary @/path/to/file.ext
# 3) Call the tool, passing the returned storageKey for each file field
curl -X POST 'https://api.elysiatools.com/en/api/tools/pdf-prompt-injection-scanner' \
-F 'pdfFile=/public/samples/pdf/brand-guidelines-pdf-example1.pdf' \
-F 'scanHiddenText=true' \
-F 'scanOffPageContent=true' \
-F 'scanTinyText=true' \
-F 'scanHiddenLayers=true' \
-F 'useStructTree=false' \
-F 'sanitizeSensitiveData=false'Send a POST request with your inputs as JSON. File parameters require a separate upload first.
POST https://api.elysiatools.com/en/api/tools/pdf-prompt-injection-scanner| Name | Type | Required | Description |
|---|---|---|---|
| pdfFile | fileupload required | Yes | — |
| scanHiddenText | checkbox | No | — |
| scanOffPageContent | checkbox | No | — |
| scanTinyText | checkbox | No | — |
| scanHiddenLayers | checkbox | No | — |
| useStructTree | checkbox | No | — |
| sanitizeSensitiveData | checkbox | No | — |
HTML result
{
"result": "<div>Processed HTML content</div>",
"error": "Error message (optional)",
"message": "Notification message (optional)",
"metadata": {
"key": "value"
}
}Add this tool to your Model Context Protocol server so AI agents can list and call it.
Add this block to your MCP client configuration:
{
"mcpServers": {
"elysiatools-pdf-prompt-injection-scanner": {
"name": "pdf-prompt-injection-scanner",
"description": "Compare safe and unsafe PDF extraction runs to detect hidden text, off-page content, tiny text, and hidden-layer prompt injection risks",
"baseUrl": "https://api.elysiatools.com/mcp/sse?toolId=pdf-prompt-injection-scanner",
"command": "",
"args": [],
"env": {},
"isActive": true,
"type": "sse"
}
}
}After connecting to the SSE endpoint, list the exposed tools:
{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list"
}Invoke the tool by its id, passing arguments built from its parameters:
{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/call",
"params": {
"name": "pdf-prompt-injection-scanner",
"arguments": {
"pdfFile": "/public/samples/pdf/brand-guidelines-pdf-example1.pdf",
"scanHiddenText": true,
"scanOffPageContent": true,
"scanTinyText": true,
"scanHiddenLayers": true,
"useStructTree": false,
"sanitizeSensitiveData": false
}
}
}Questions or issues? Contact [email protected]