The security scanner, and what it does not check
Settings, System, Safety, Security events runs a prompt-injection scanner on content flowing through agent turns. It is not a scan of everything in your vault, and the app says so in its own words.
Last checked against the app on · View as Markdown
Steps
- Open Settings, then System, then Safety, then the Security events row, then Review.
- The page lists what it actually scans: content that flows through a tool result or an agent turn, and wire messages once they enter one.
- It also lists, in its own words, what it does not cover: your vault at rest unless content is actively flowing through a turn, anything past the first 128 KiB of a single input, your own typed chat messages, and camera or OS-login intrusion detection.
How to tell it worked
The page itself states both lists rather than leaving either to be assumed.
If it does not work
- You assumed importing or writing a note scans it for injected instructions.
- It does not. Vault content is only scanned when it flows through a tool result or an agent context, not on write or import.
- You pasted a very long document and want to know if all of it was checked.
- Only the first 128 KiB of any single input is scanned. Content beyond that is not.