Skip to content

Prompt injection detection for Claude Agent SDK

Arcjet prompt injection detection evaluates each incoming prompt for injection patterns inside your application before it reaches the AI provider. Detected attacks are blocked before the AI call is made, protecting both your application behavior and your AI budget.

What is Arcjet? Arcjet is the AI agent runtime security platform. Discover the agents running in your organization, enforce policy across every action, prompt, and tool call, and keep the evidence to prove what happened. Detect prompt injection, authorize agent tool calls, redact PII, and block bots and abuse.

This example screens inbound user text for prompt injection before the model runs.

We assume you already have a Claude Agent SDK project set up. For helper options and denial behavior, see the Claude Agent SDK agent guard.

Install the dependencies:

Terminal window
# Export your Arcjet API key from https://console.arcjet.com
export ARCJET_KEY="ajkey_..."
npm install @arcjet/guard @anthropic-ai/claude-agent-sdk

Create the example:

agent.ts
import { query } from "@anthropic-ai/claude-agent-sdk";
import { launchArcjet, detectPromptInjection } from "@arcjet/guard";
import { guardHooks } from "@arcjet/guard/claude-agent-sdk/v0";
const arcjet = launchArcjet({ key: process.env.ARCJET_KEY! });
export async function runAgent(sessionId: string, userText: string) {
for await (const message of query({
prompt: userText,
options: {
sessionId,
hooks: guardHooks(arcjet, {
sessionId,
inbound: {
action: "message.received",
rules: ({ prompt }) => [detectPromptInjection()(prompt)],
},
}),
},
})) {
void message;
}
}

Then start or invoke the agent with a test prompt.

Requests appear in your Arcjet dashboard in real time.

Need help with anything? Email support@arcjet.com to get support from our engineering team.

Discussion