LLM Guard is a Python security toolkit for developers building applications around large language models. It checks prompts and generated responses for risks such as prompt injection, sensitive data exposure and harmful language. The project is archived and no longer maintained, including its associated models on Hugging Face.
Its checks cover both sides of a conversation. Prompt scanners can detect injection attempts, secrets, invisible text and toxic language, while anonymization can remove identifying information before a prompt reaches a model. Other checks let applications restrict topics, code, competitor mentions or particular text patterns, and apply token limits.
Response scanners address a different set of concerns: sensitive content, bias, malicious URLs, relevance and factual consistency. They can also check JSON, detect refusals, compare the response language with the prompt language and restore anonymized information. These are separate checks, so developers can choose the ones that fit their application's risks rather than apply every restriction to every exchange.
LLM Guard is an application component rather than a chat interface or model runner. It supports deployment as an API and includes an example integration with ChatGPT. The code is open source under the MIT license. Its scanner selection covers content policy checks as well as security checks, including sentiment, gibberish and estimated reading time.
Claim this page and we'll verify you by hand. LLM Guard gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find LLM Guard?Promote it
Something wrong or outdated on this page?
7.5KUpdated 1 month agoApache-2.0
#Guardrails#Structured output
Guardrails AI is an open-source Python framework for developers who need to check what goes into an LLM and what comes back. It runs within your application or as a self-hosted service. The framework uses the Apache 2.0 license and helps address risks such as policy violations, hallucinations, and data leakage before outputs reach users.
59.9KUpdated 55 minutes ago
#Guardrails#MCP#Multi-user access
7.2KUpdated 23 hours ago
Docker#Guardrails#LLM tracing#Tool calling
1.5KUpdated 3 years agoApache-2.0
Web#Guardrails#Semantic search
496Updated 3 years agoApache-2.0
Docker · Web#Guardrails#Semantic search
27.3KUpdated 20 hours agoMIT
macOS · Windows · Linux#Code execution#MCP#Tool calling
LiteLLM gives platform teams one place to manage access to LLMs across providers. Its self-hosted AI gateway puts cloud services and internal or locally hosted models behind an OpenAI-compatible API, so applications can change models without changing their integration. Developers can also use its Python SDK directly.
NeMo Guardrails is an open-source Python toolkit for developers who need control over how an AI assistant responds and uses tools. It runs within your application or as a self-hosted server, including in Docker. The library uses the Apache 2.0 license.
Rebuff is a prompt injection detector for developers building LLM applications that accept untrusted input. It combines checks for suspicious prompts with a record of past attacks and tests for leaked prompt content. The project is archived and no longer maintained.
Vigil is a self-hosted security scanner for developers and researchers who want to check LLM inputs and responses for prompt injection, jailbreak attempts, and other suspicious content. It combines several detection methods and includes attack signatures and datasets, so teams can assess known threats without building every detector themselves. It is experimental alpha software for research and is open source under Apache 2.0.
Cua gives AI agents access to computers they can inspect and operate, with tools for desktop automation, local virtual machines, and hosted fleets. It's for developers building agents that work across native apps and browsers, or evaluating how well those agents complete computer tasks. You bring the agent and model.