shellward
View on GitHubAI 应用合规网关 · 一行命令体检 AI 项目的「数据出境 / 硬编码密钥 / 个人信息暴露」(网安法·PIPL·等保2.0·数据出境·AI标识),并给出境内模型替代建议;可作运行时防护拦截注入与数据外泄 · 中文优先 · 零依赖 · 开源
ShellWard is a zero-dependency AI agent security and China-compliance gateway. It scans projects for cross-border data flow, hardcoded secrets and Chinese PII (PIPL/CSL/MLPS), then blocks prompt injection, data exfiltration and dangerous tool calls at runtime via SDK, MCP server or CLI.
Use Cases
Scan an AI project for China compliance risks (PIPL/CSL/MLPS/cross-border data/AI labeling)Block prompt injection in agent inputs and tool outputsPrevent data exfiltration when an agent reads PII then calls email/HTTP/curlDetect Chinese PII such as ID card, mobile, UnionPay bank card, plus API keys and JWTScan MCP tool definitions for poisoning, hidden instructions and rug-pull changesAdd runtime guardrails to agent tool calls via SDK or MCP serverEnforce compliance gates in CI or a GitHub Action PR checkProduce a file:line compliance report with evidence and verification gatesGet domestic LLM alternatives with OpenAI-compatible base_url for migrationAudit AI responses for canary leaks and sensitive exposure
Built With
- Language
- TypeScript
- Frameworks
- LangChain · AutoGPT · OpenAI Agents SDK · Claude Code · Cursor · OpenClaw · Dify · Coze · Hermes Agent · Claude Desktop · MCP
Tags
ai-security · prompt-injection · dlp · guardrails · pii-detection · mcp-security · data-exfiltration · llm-security · ai-firewall · compliance · china-pipl · zero-dependency · cli · agent-skill · mcp-server · audit-log