Paste any prompt. ReasonGate inspects it for prompt injection / jailbreak, tells you which signal fired and why, and emits a structured, auditable record. This demo runs the zero-dependency rule core — no data leaves the server, no API keys.
A support agent with send_email and transfer_funds tools reads a
retrieved customer record. The record below hides an instruction — but reworded, with no
"ignore previous instructions" signature, so detection does not catch it. Watch the second layer:
the action gate blocks the tool call anyway, because its destination is quoted from untrusted content.
pip install reasongate