AI SAFETY

A firewall for people who actually use AI.

Not enterprise security software. Seven plain-language skills for the risks that hit normal people every week — what not to paste, poisoned documents, AI scams, over-permissioned connectors, confident wrong answers. Free to read. Defensive only.

The threats, and what stops each

Real, current AI risks — each mapped to the skill that addresses it. Every skill is free to read; you run it and judge the output yourself.

THREAT

Prompt injection

A document, email, or web page hides instructions that hijack your AI — the top agent-era attack (OWASP LLM01).

Defended by Spot the Prompt Injection →
THREAT

Data leakage

You paste a password, a card number, or someone else’s private data into a chatbot that keeps it.

Defended by What Not to Paste →
THREAT

AI scams & deepfakes

A cloned voice or flawless phishing message asks for money, a code, or a click. Fraud losses are climbing fast.

Defended by Spot an AI Scam →
THREAT

Over-permissioned tools

A connector or agent asks for far more access than the task needs — and could reach everything if compromised.

Defended by Vet a Connector →
THREAT

Confident wrong answers

The AI invents a fact, a citation, or a number and says it with total confidence. You act on it.

Defended by Fact-Check Your Own AI →
THREAT

Your data, their training

A free tool quietly trains on your chats and keeps them — and you never saw the toggle.

Defended by Data Privacy Check →

How you actually use it

01

Set it up once

Run the privacy and connector checks, turn on 2FA. About 30 minutes, then it's done.

02

Build the reflexes

Before you paste, before you trust an answer, before you connect a tool — one quick check.

03

Contain a slip

When something goes wrong anyway, the After-a-Leak plan gets you moving in the first 15 minutes.

The seven skills

After a Leak

Untested

The calm containment plan for the moment you realize you shared something you shouldn't have — pasted a password into a chatbot, sent data to the wrong place, got phished, or found an account compromised. What to do first, in order, to limit the damage.

security

Data Privacy Check

Untested

Decodes what an AI tool actually does with your data — does it train on your chats, how long does it keep them, can you turn that off — by reading its settings and privacy terms in plain language, so you can decide what's safe to use it for.

security

Fact-Check Your Own AI

Untested

Pressure-tests an AI's answer before you trust it — spotting the confident-sounding claims that might be invented, and telling you exactly which parts to verify before you act, cite, or send.

security

Spot a Fake Number

Untested

Checks whether the numbers in a pitch — income claims, "results", conversion stats, "students earning X" — behave like something measured or something generated. It doesn't tell you the person is lying; it tells you whether their figures have the fingerprints of real data, which is a question you can actually answer from the post itself.

security

Spot an AI Scam

Untested

Helps you check whether a suspicious message, call, or offer is an AI-powered scam — deepfake voices, AI-written phishing, fake "AI support," a too-good investment — and tells you the safe next move without tipping off the scammer.

security

Spot the Prompt Injection

Untested

Checks a document, email, web page, or file for hidden instructions designed to hijack your AI — the 2026 version of a booby trap. Before you feed something to a chatbot or an AI agent that can act for you, this catches text that's secretly telling the AI to do something you didn't ask for.

security

Vet a Bundle

Untested

Runs the checks before you pay for a mega-bundle — "100,000 digital products", "thousands of ebooks", "500+ AI prompts", a lifetime course vault — so you find out what you're actually getting while your money is still yours. Built around the three things these listings almost never say out loud: how it's delivered, how much of it is duplicates, and whether it was the seller's to sell.

security

Vet a Connector

Untested

Before you connect an AI tool to your accounts — an MCP server, a browser extension, a "link your Gmail/Drive" integration, an autonomous agent — this walks you through what access it's really asking for and what could go wrong, so you grant the least it needs.

security

What Not to Paste

Untested

Your personal firewall for AI. Before you paste something into a chatbot, this checks it for the things that shouldn't leave your control — passwords, full card numbers, other people's private data, work secrets — and shows you a safe, redacted version that still gets the job done.

security

Vet us too.

One of these skills is about checking a connector before you trust it. Run it on ours. We'd rather you verify than take our word — that's the whole brand.

Vet a Connector →