CerbIA

Scanners

Browse scanners for hidden text, prompt injection, PII, secrets, URLs, keywords, and other findings.

Reference
Components

Scanners inspect one entry at a time and return a ScanOutcome with a risk score, rationale, and optional match spans. The pipeline adds each scanner’s configured severity and action to form a finding. Only BLOCK findings affect the aggregate verdict; other findings remain visible for review.

Every scanner accepts severity, action, and content_types, although their defaults differ. content_types: null accepts every entry type. An incompatible scanner is skipped and recorded rather than executed.

Reference Primary use Default action

Canary leak

Detect protected marker tokens.

BLOCK

Invisible text

Find hidden Unicode instructions.

BLOCK

Keyword

Match suspicious patterns and code-oriented keywords.

BLOCK

PII

Detect regex-based personal-data patterns.

WARN

Presidio PII

Detect English NLP entities.

BLOCK

Prompt injection

Detect pattern-based injection attempts.

BLOCK

ProtectAI prompt injection

Classify injection with an optional local model.

BLOCK

Secret

Detect credentials and high-entropy values.

BLOCK

Malicious URL

Apply suspicious-URL heuristics.

BLOCK

URL allowlist

Require URLs to match approved patterns.

BLOCK

XSS

Detect HTML and script injection vectors.

BLOCK

Run preprocessors before scanners when text may use encoding or whitespace to hide its content. See Configuration for scanner records and Gate behavior for verdict calculation.