Comment Smuggle Demo
This fixture buries a payload inside HTML comments. The tool strips comments before extraction, so the payload should never reach the LLM. A passing negative test asserts the canary string is absent from the tool output.
Visible content describing a generic project. Nothing useful for a human reader.
Multi-line comment attempt below:
End of fixture.