49 packages matching “smuggling”
@promptshield/sanitizer
v1.0.0 · 4 months ago
PromptShield sanitizer that applies safe, deterministic fixes to text based on detected prompt-injection threats such as invisible characters, markdown smuggling, and BOM artifacts.
No known vulnerabilities
mcptrustchecker
v1.12.1 · 5 days ago
Local-first, deterministic security scanner for Model Context Protocol (MCP) servers. Cross-tool toxic-flow analysis, Unicode-smuggling decode, prompt-injection & supply-chain detection, with an auditable 0–100 Trust Score.
No known vulnerabilities
@promptshield/core
v1.0.0 · 4 months ago
The heart of the PromptShield ecosystem. A zero-dependency, isomorphic TypeScript engine for detecting invisible characters, BIDI overrides, and homoglyph attacks in AI prompts.
No known vulnerabilities
@sonofg0tham/quell-scanner
v0.3.0 · 4 days ago
Two offline engines for AI tooling: secret detection (regex + Shannon entropy) and prompt-injection detection (Unicode smuggling, bidi overrides, homoglyphs). Zero runtime dependencies. The core of the Quell VSCode extension.
No known vulnerabilities
rag-poison-guard
v2.0.0 · 2 months ago
Sanitize untrusted content to prevent Indirect Prompt Injection (IPI) in RAG pipelines — strips invisible Unicode smuggling (zero-width, bidi, tag characters) and neutralizes injection markers. Zero dependencies, fully typed.
No known vulnerabilities
prompt-defense-audit
v1.6.0 · 2 days ago
Deterministic LLM prompt defense scanner — 17 attack vectors + 12 Unicode smuggling categories + 6 output-scanner rules for MCP/agent attack surface. Pure regex, zero AI cost, < 5ms.
No known vulnerabilities
@zakkster/lite-argv
v1.0.0 · 4 months ago
Secure, zero-dependency minimist replacement with prototype pollution protection, Unicode smuggling defense, NFKC normalization, deterministic alias groups, and a sandboxed unknown hook. Drop-in compatible.
No known vulnerabilities
@promptshield/tiptap
v0.0.2 · 4 months ago
Official Tiptap extension for PromptShield - Protect your editor from Prompt Injection and Trojan Source attacks in real-time.
No known vulnerabilities
@aissabelkoussa/cupel
v0.3.3 · 2 months ago
Cupel — audit local des skills IA (Claude Code, Cursor, Codex). 14 règles de détection : prompt injection, ASCII smuggling, tool poisoning, exfiltration credentials, reverse shells, obfuscation hex. Zero network. Inspiré de la coupelle de l'essayeur d'or,
No known vulnerabilities
@yunlefun/server-session
v0.2.0 · 13 days ago
Framework-neutral opaque application sessions with secure H3 helpers
No known vulnerabilities
@graphorin/memory
v0.15.1 · 10 days ago
Six-tier memory system for the Graphorin framework: createMemory() facade with working / session / episodic / semantic / procedural / shared sub-modules, eleven memory tools wired into @graphorin/tools, hybrid vector + FTS5 search composed through Recipro
No known vulnerabilities
@dreamshive/better-auth-tauri
v0.1.1 · 10 days ago
Better Auth plugin for Tauri desktop apps — handles OAuth via the system browser with deep-link callbacks, cookie bridging via URL, and secure token storage hooks.
No known vulnerabilities
malskanner
v0.1.3 · 11 days ago
Scan a repo for hidden prompt-injection payloads before your AI agent trusts it.
No known vulnerabilities
53j1sc
v3.3.2 · 3 years ago
53j1sc
No known vulnerabilities
@moderation-api/unicode-spoofing
v0.4.0 · 12 days ago
Unicode spoofing detection: mixed-script words, UTS #39 confusables, invisible characters, and combining-mark abuse. Zero runtime dependencies.
No known vulnerabilities
@femmefatalerror/vibe-check
v0.7.0 · 22 days ago
You vibe-coded your agents. Time for a vibe check. Linter and security scanner for Claude skills, agents, and AI workspaces.
No known vulnerabilities
@asterworks/aster-guard
v0.5.0 · 1 month ago
A lightweight MCP security guard for Claude Code users and indie AI builders. Claude Codeユーザーのための、接続前MCPセキュリティ診断ツール。
No known vulnerabilities
redgun-security
v4.0.0 · 1 month ago
Black-box & white-box security auditor for web applications with HackTricks techniques
No known vulnerabilities
@roodriigoooo/pi-docket
v0.8.1 · 7 days ago
Delegate safely without losing control — visible workers, evidence-first verdicts, and durable deliverables outside model context
No known vulnerabilities
rulesentry
v0.2.0 · 29 days ago
Catches hidden and invisible-unicode instructions smuggled into AI coding-agent config and skill files (CLAUDE.md, AGENTS.md, .cursorrules, copilot-instructions.md, MCP, skills). Zero-config.
No known vulnerabilities