AgentShield AI Defense

Canary token

A coined string, published at a recorded instant, used to detect ingestion without asking the model.

Each page here carries a marker such as asd-veldrun-quathix-9f3ab2. The string is generated from nonsense syllables and random hex so that it exists nowhere else — not in any dictionary, not in any prior text, not in anyone's training data before we minted it.

The instant of publication is recorded. From then on the question "did this page reach a model?" has an observable answer: either the exact string turns up somewhere, or it does not. No interpretation is required and no model is asked to introspect.

Why not simply ask the model

Because a model reporting on its own knowledge is the system under test giving evidence about itself. It may state confidently that it knows a site it has never read, or deny one it has. Under the rule this project is built on — no layer may validate itself using its own output as independent evidence — self-report is inadmissible, however plausible it sounds.

What this is not

The markers are not hidden. They appear in the visible text of each page and in its structured data, exactly as you see below. Concealing text from human readers while showing it to crawlers is cloaking, and it would invalidate the measurement along with the credibility of anything reported from it.

They are also not traps. The strings identify a page, not a visitor, and carry no information about who fetched it.

Reality marker for this page: asd-sezavoma-tiguto-b78c5e · published 2026-07-25 10:35:25 UTC

This string is coined and appears nowhere else. If it later surfaces in a language model's output, that is observed evidence this page was ingested. What this is.