Cloakscan
Scans the page you're on for text hidden from view, so you know whether it was written for you or for the AI agent reading over your shoulder.
CloakScan
Scans the page you're on for text hidden from view, so you know whether it was written for you or for the AI agent reading over your shoulder.
Date: 2026-09-14
Form factor: Browser extension (Manifest V3)
Browser surface: toolbar popup, on-demand content script (via activeTab + scripting)
Status: Prototype
What it is
CloakScan checks whatever page you're currently viewing for text a person would never notice: white-on-white spans, elements shoved off-screen, font sizes rounded down to nothing, HTML comments, and zero-width characters spliced into ordinary sentences. Click the toolbar icon, click Scan, and it outlines each one directly on the page and lists what it found in plain language, not a jargon score.
Why it has to be an extension
Every technique CloakScan looks for exploits the gap between what a browser renders and what a script or an AI agent reads off the raw DOM. Catching that gap means reading the fully computed styles and the complete HTML of the tab you're actually on, then drawing outlines and badges directly onto that page. A page has no reason to report its own hidden text, and a separate website you visit can't see another site's DOM at all — only a content script running inside the tab itself can do this.
Who it serves
Anyone who now routinely hands a page to an AI agent or browsing assistant: asking Comet or Atlas to "check reviews and buy the best one," or pasting an article into a chatbot to summarize. The specific risk is text on the page telling that agent something different from what you'd tell it yourself, and doing so without your knowledge. This isn't hypothetical: Brave documented attackers hiding instructions in white-on-white text and HTML comments to make Comet fetch one-time passwords and access banking portals, and in March 2026 researchers disclosed a flaw ("ShadowPrompt") letting any website silently inject prompts into Anthropic's Claude Chrome extension.
Why it could be profitable
Free tier: manual, per-tab scans — everything in this prototype. Paid tier ($3–5/month): scanning that runs automatically as you browse instead of waiting for a click, and scan history synced across devices. A further "pause the agent when this page scores high risk" feature is worth naming honestly as aspirational — today's agentic browsers don't expose a general hook that lets a third-party extension halt their action queue, so that piece depends on a browser API that doesn't exist yet. A second, maybe steadier, revenue line is B2B: content and marketing teams auditing their own pages before publish, in case a compromised CMS plugin or a user-generated comment section slipped hidden text past them.
The demand case rests on prompt injection being an active, unresolved threat rather than a theoretical one — OWASP's Top 10 for LLM Applications has ranked it the #1 risk for three years running as of its August 2026 edition, and named incidents (Comet, Claude's ShadowPrompt flaw, Brave's later screenshot-injection research) keep landing every few months. What's unproven is whether a consumer will pay for a scanner rather than just trusting the AI vendor to fix it — no comparable product has demonstrated that conversion yet, and every vendor involved has said publicly that prompt injection has no reliable fix.
How to load it in Chrome
- Open
chrome://extensionsand turn on Developer mode. - Click Load unpacked and select this folder's
extension/directory. - Visit any page, click the CloakScan icon in the toolbar, and click Scan this page. (This prototype ships without a custom icon, so Chrome shows its default puzzle-piece badge for the toolbar button.)
How to try the demo
- Open
index.htmldirectly in a browser — the sample article is embedded inline in the page, so it works straight fromfile://with no server. - Click the CloakScan icon in the mock toolbar, then click Scan this page in the popup.
The demo simulates content.js's on-page annotation step (script.js draws the outlines and badges onto the mock article, since there's no live tab for chrome.scripting to inject into). The popup's scan, summarize, and copy logic is the same extension/popup.js that ships in the real extension.
Permissions, and why each one
| Permission | Why it's needed |
|---|---|
activeTab |
Lets the popup ask for the tab you're currently viewing, but only for the instant after you click the icon — no standing access to your browsing. |
scripting |
Injects content.js into that one tab, on that one click, to run the scan. |
storage |
Keeps the last scan result locally so reopening the popup on the same tab doesn't lose it. |
There's no host_permissions entry and no <all_urls>. CloakScan never touches a page until you click it there.
What's in this prototype
- Six detection heuristics: color-matched text, off-screen positioning, shrunk-to-invisible sizing, aria-hidden elements carrying instruction-like phrasing, HTML comments, and zero-width Unicode characters.
- On-page outlining and numbered badges pointing at each finding, in the real extension.
- A "copy visible-only text" button that strips the flagged content so you can safely hand the rest to a chatbot.
- The last scan result kept per session via
chrome.storage.local. - A demo harness with a fabricated gear-review article carrying one planted example of each hidden-text technique.
Roadmap
- Continuous background scanning as a paid tier
- Cross-device scan history sync
- A shareable "page hygiene" report link for the B2B audit use case
- A larger keyword/heuristic library built from real reported cases instead of a hand-written list
- A Firefox-compatible build
Sources
- Brave: Agentic Browser Security — Indirect Prompt Injection in Perplexity Comet — the white-on-white-text and HTML-comment attacks this extension is built to catch
- The Hacker News: Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website — the March 2026 "ShadowPrompt" disclosure
- Brave: Unseeable Prompt Injections in Screenshots — follow-up research showing the problem spans multiple AI browsers, not just one
Requirements
CloakScan — Requirements
Goals
- Detect the common ways a web page hides text from a human reader while leaving it readable to a script or an AI agent.
- Surface findings on the page itself, not just in a popup list, so the user can see exactly where the hidden content sits.
- Give the user a way to extract only the human-visible text of a page, for safely pasting into a chatbot.
- Request the minimum permissions the detection actually needs — no standing access to browsing history or page content.
Primary user
Someone who hands pages to an AI browsing agent (Comet, Atlas, Gemini-in-Chrome) or copy-pastes page content into a chatbot for summarizing, comparing, or acting on their behalf. They are not a security researcher; they want a plain answer to "is there something on this page trying to steer whatever's reading it," triggered on demand rather than running continuously in the background.
Functional requirements
- FR1: The toolbar popup has a single primary control: a "Scan this page" button.
- FR2: On click, the extension injects a scan into the active tab using
activeTab+scripting, with no persistent content script and nohost_permissions. - FR3: The scan detects text where the computed foreground and background colors are within a near-zero contrast ratio.
- FR4: The scan detects text in elements positioned off-screen via absolute or fixed positioning.
- FR5: The scan detects text in elements shrunk to 1px font size, or to a 1x1px box with overflow hidden.
- FR6: The scan detects elements marked
aria-hidden="true"whose text matches a list of instruction-like phrases. - FR7: The scan detects HTML comments whose content matches the same instruction-like phrase list.
- FR8: The scan detects zero-width Unicode characters (U+200B, U+200C, U+200D, U+FEFF, U+2060) embedded in visible text.
- FR9: Each finding records a type, a confidence level, and a short snippet of the flagged text.
- FR10: The extension outlines each flagged element on the live page and labels it with a numbered badge.
- FR11: Re-running a scan on the same tab clears the previous run's outlines and badges before drawing new ones.
- FR12: The popup lists every finding with a human-readable label and its snippet.
- FR13: The popup offers a "copy visible-only text" action that reconstructs the page's text with all flagged content excluded.
- FR14: The last scan result for the current tab persists in
chrome.storage.localso reopening the popup doesn't lose it. - FR15: The popup works identically, using the same markup, styles, and script, whether it's the real
extension/popup.htmlor the demo harness's embedded copy.
User stories
- As someone about to ask an AI agent to summarize a page, I want to check it for hidden instructions first, so I know the agent is acting on what I read, not on something planted for it.
- As someone who just had a chatbot give a suspiciously confident answer about a product, I want to see if the source page had text steering that answer, so I can tell whether to trust it.
- As a user of an AI browsing agent, I want to know before granting it a task whether the current page is trying to manipulate it, so I can cancel before it acts.
- As a privacy-conscious user, I want the extension to run only when I click it, so I'm not trading "protect me from hidden text" for "read everything I browse."
- As someone who wants to paste an article into a chatbot myself, I want a clean, hidden-text-free copy of the visible content, so I'm not accidentally pasting an injected instruction along with it.
Extension surfaces
- Toolbar popup (
action.default_popup) — the only UI; hosts the scan button, findings list, and copy-clean-text control. - On-demand content script (
chrome.scripting.executeScript,content.js) — runs the detection and page annotation inside the active tab, invoked from the popup rather than declared as a persistent content script. chrome.storage.local— persists the most recent scan result.
Non-functional requirements
- No
host_permissionsor<all_urls>— every scan requires an explicit user click viaactiveTab. - Detection runs client-side only; no page content is ever sent to a server.
- The popup renders correctly at the 360px width used in this prototype, without horizontal scrolling.
- A scan on a typical article-length page completes without a visible delay (under roughly one second).
- The heuristics err toward flagging borderline cases rather than missing an actual hidden-text pattern, since a false positive costs a glance and a false negative costs the whole point of the tool.
Out of scope (for the prototype)
- Continuous, always-on scanning as you browse (the paid-tier idea in the README).
- Any mechanism to actually pause or intercept an AI browsing agent's actions — no such hook exists in any shipped agentic browser today.
- Cross-device sync of scan history.
- Detection of prompt injection delivered through images, audio, or PDF content rather than page text.
- A custom extension icon; this prototype ships with Chrome's default toolbar badge.
Open questions
- Which instruction-like phrases produce the fewest false positives on ordinary marketing or legal boilerplate, which also uses phrases like "do not" and "as a reminder"?
- Should the color-contrast and off-screen heuristics have adjustable sensitivity, given legitimate accessibility patterns (skip links, visually-hidden labels) can resemble the attack patterns being flagged?
- Is there a monetizable version of the B2B "publish hygiene" audit that doesn't require the extension to also work as a crawler, which is a different product?