Paste your bot's system prompt. Get an A-F security grade + top 3 issues. 100% self-check — your bot, your prompt, your review.
You spend 35 seconds on steps 1 and 2. Our model spends 60 on step 3.
The full instructions you give your AI agent. Don't worry — we don't store it.
One-click legal safeguard. We only scan bots you own or operate — never third parties.
OWASP LLM Top 10 analysis: prompt injection, data leakage, excessive agency, prompt leakage.
Free, instant, and your prompt is never stored. Results stay on your screen.
Running OWASP LLM Top 10 analysis across 4 vulnerability classes.
Your system prompt has been graded against the OWASP LLM Top 10 framework.
Get the full top 10 issues + a 30-day action plan tailored to your bot. Delivered within 24 hours.
Secure checkout via Stripe · 7-day refund window
Four high-impact classes from the OWASP LLM Top 10 — the ones that hit SMB chatbots hardest.
User input that overrides the system prompt — direct injection, indirect via documents/RAG, multi-turn setup, encoding chains.
Whether the prompt leaks internal docs, pricing, customer data, API keys, or other secrets through model outputs.
Tool-calling permissions, irreversible actions, lack of human-in-the-loop, scope creep in agentic workflows.
Can a user extract the system prompt verbatim? Reverse-engineer hidden rules? Discover the model and version?
If yours isn't here, email mattgale87@gmail.com.
No. The prompt is sent over TLS to the grading function, used for the analysis, and discarded. We do not write your prompt to disk, database, or any log. The analysis result (grade + findings) is held in your browser session only.
No — and we built it that way on purpose. The attestation checkbox is a legal safeguard. We only grade prompts you own or operate. Scanning third-party chatbots raises CFAA / Terms of Service issues we want to avoid entirely.
GaleScan is automated, instant, and free — it gives you a top-3 issues triage in 90 seconds. The $149 Snapshot is a manual review by Matt Gale (H1 researcher, Zest V2 auditor) with 25+ targeted probes, a branded PDF, and a 15-min walkthrough video delivered in 5 business days. GaleScan is your "should I worry?" check; Snapshot is your "show me exactly what to fix" deliverable.
The full top 10 vulnerabilities (not just the top 3 surfaced here), a 30-day prioritized action plan, drop-in prompt patches for each issue, and a PDF report white-labeled for your team. Delivered within 24 hours. The $49 is a stepping-stone to the $149 Snapshot and the $5K audit engagement if you need deeper work.
They measure the same thing (OWASP LLM Top 10 risk surface) but with different fidelity. GaleScan's grade is a quick triage from a single LLM analysis pass — fast and free, but with less precision than 4-6 hours of manual review. If your GaleScan shows Critical or High, the $149 Snapshot is the right next step.
Because the funnel works: you grade your bot, you see the issues, you want the full fix — that's where the $49 Deep Scan, $149 Snapshot, and $5K audit live. Free grading is the top of the funnel. We make money on the resolutions, not the read.
Free 90-second grade. No signup. Your prompt never leaves the request.
Grade My Bot →