What would your agent swallow?
Paste text, drop a file, point it at a GitHub repo or scan an image. This runs the Sunglasses pattern engine ported to a Cloudflare Worker, not the pip package itself, so it can trail the pip release. The build answering you right now is shown below, read live from the engine. Your content is scanned in memory and discarded.
Scans the repo's agent input surfaces README · CLAUDE.md · AGENTS.md · .cursorrules · MCP configs · llms.txt the files an AI agent actually reads. Fetches only from GitHub's raw domain. Sunglasses is an agent input scanner, not a code auditor.
The pip release is v0.5.9 with 1554 patterns. This demo is a port of that engine and the two numbers above are read live from it, so when the port trails the release you can see it here.
Known attack signal
The content matched one or more tested attack patterns. With the pattern ID and the exact matched text shown, so you can verify the call yourself. Never a naked red light.
Flagged for review
Suspicious but not conclusive. The honest middle. In production this routes to human review instead of silently blocking your pipeline.
No known patterns fired
A clean result is a confidence floor, not a guarantee. Novel attacks with no known signature pass any scanner. We say that out loud.
False positive? Tell us and we fix the pattern. Every report makes the engine sharper for everyone. Report it in one click. Full honest scope: what we catch vs what we don't and the numbers behind this engine are published and reproducible on the benchmark page.
The demo is the appetizer. The real thing runs local first in your pipeline. No caps, no rate limits, MIT licensed.