Project overview
Place the scanner between untrusted content, model output, and tool execution, or wrap a line-delimited stdio MCP server with its proxy. It detects prompt injection, credential disclosure, exfiltration, and destructive actions before forwarding a call, redacts secrets, and returns structured reasons for enforcement. The scanner makes no network calls and ships as a Rust CLI with Node and Python wrappers.
Repository facts
- Primary language
- Rust
- License
- MIT
- Repository updated
- Jun 22, 2026
- Default branch
- main
Resource types
CLI app
Use cases
Security and privacy
Runtime
Local
Capabilities
Security guardrail