Vigil is a self-hosted security scanner for developers and researchers who want to check LLM inputs and responses for prompt injection, jailbreak attempts, and other suspicious content. It combines several detection methods and includes attack signatures and datasets, so teams can assess known threats without building every detector themselves. It is experimental alpha software for research and is open source under Apache 2.0.
The scanners use YARA rules, a transformer model, and text similarity against a vector database of attack examples. Prompt-response similarity and sentiment analysis provide additional checks. Each scanner can contribute to the detection result, which reports matched rules, model scores, and similar attack texts rather than only a single verdict.
Teams can add custom YARA signatures and their own attack datasets. The vector database can also update with detected prompts. Canary tokens support checks for prompt leakage and goal hijacking, where an input tries to redirect a model away from its intended task.
Vigil runs within a Python application or as a REST API on your own server. A Streamlit playground provides a web interface for trying scans. It supports local embeddings as well as embeddings from OpenAI; choosing OpenAI sends embedding requests to that external service. Its intended use is security research, and its detection approach targets known attack techniques without guaranteeing that every injection will be caught.
Claim this page and we'll verify you by hand. Vigil gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find Vigil?Promote it
Something wrong or outdated on this page?
1.5KUpdated 3 years agoApache-2.0
Web#Guardrails#Semantic search
Rebuff is a prompt injection detector for developers building LLM applications that accept untrusted input. It combines checks for suspicious prompts with a record of past attacks and tests for leaked prompt content. The project is archived and no longer maintained.
7.2KUpdated 23 hours ago
Docker#Guardrails#LLM tracing#Tool calling
7.5KUpdated 1 month agoApache-2.0
#Guardrails#Structured output
Guardrails AI is an open-source Python framework for developers who need to check what goes into an LLM and what comes back. It runs within your application or as a self-hosted service. The framework uses the Apache 2.0 license and helps address risks such as policy violations, hallucinations, and data leakage before outputs reach users.
59.9KUpdated 55 minutes ago
#Guardrails#MCP#Multi-user access
3.2KUpdated 3 months agoMIT
#Guardrails
LLM Guard is a Python security toolkit for developers building applications around large language models. It checks prompts and generated responses for risks such as prompt injection, sensitive data exposure and harmful language. The project is archived and no longer maintained, including its associated models on Hugging Face.
27.3KUpdated 20 hours agoMIT
macOS · Windows · Linux#Code execution#MCP#Tool calling
NeMo Guardrails is an open-source Python toolkit for developers who need control over how an AI assistant responds and uses tools. It runs within your application or as a self-hosted server, including in Docker. The library uses the Apache 2.0 license.
LiteLLM gives platform teams one place to manage access to LLMs across providers. Its self-hosted AI gateway puts cloud services and internal or locally hosted models behind an OpenAI-compatible API, so applications can change models without changing their integration. Developers can also use its Python SDK directly.
Cua gives AI agents access to computers they can inspect and operate, with tools for desktop automation, local virtual machines, and hosted fleets. It's for developers building agents that work across native apps and browsers, or evaluating how well those agents complete computer tasks. You bring the agent and model.