Skip to content
ai-supply.store
探索分类排行榜社区Agent APIFAQ
登录免费注册
catalog / Cybersecurity / Vigil
⛨GuardrailCybersecurityFree

Vigil

Library and REST API that scans LLM prompts for prompt injection and jailbreaks using an ensemble of vector, transformer, YARA, and canary detectors.

@ai-supply
安装量36k
⟳ upstream v0.10.3-alpha · updated 2y ago
↗ 源代码仓库
← More CybersecurityCybersecurity leaderboard →How we grade security →Source ↗
! Grade B · 75/100 · ReviewSecurity assessment
✓No compromise signals10capabilities surfaced1known CVE7of 20 OWASP controls clear
Vulnerable dependenciesExternal endpoints declared · expectedExternal endpoints declared · expectedSuspicious code patterns · expected
scanned 1mo ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓

Vigil — LLM prompt injection & jailbreak detection

Vigil is a Python library and REST API for scanning LLM prompts and responses for prompt injection, jailbreaks, and other risky inputs before they reach your model. It layers several independent detection scanners so no single technique becomes a blind spot.

Key features

  • Ensemble scanners: vector-database similarity to known attacks, a transformer classifier, YARA/heuristic rules, prompt-response relevance, and canary-token leak detection
  • Ships curated embeddings and signatures for documented prompt-injection and jailbreak techniques
  • Runs as an embeddable library or a standalone REST API service
  • Configurable per-scanner thresholds and pluggable custom detectors
  • Local-first: works with self-hosted embedding models, so prompt data never leaves your stack

Vigil sits in front of any LLM as an input/output firewall, giving agent builders an auditable guardrail layer that flags adversarial inputs instead of silently passing them through.

Curated mirror of the open-source Vigil (Apache-2.0). Get it from the source.

Rating rank
#1
of 19 in Cybersecurity
Install rank
#13
of 19 in Cybersecurity
Security score
75/100 · B
review
Security rank
#13
of 19 in Cybersecurity
Installs
36k
cat avg 85k
This listing vs category average
Installs
this
cat avg
Security (of 100)
this
cat avg
Adoption trend
See the Cybersecurity leaderboard →
! Security: Review · 7575/100 · grade Bscanned 1mo ago
✓ no compromise signals11 risk-surface · 7/20 OWASP controls flagged

Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.

Control card · high confidence (static)
framework: pytestcovers: prompt-injectioncovers: jailbreakcovers: secrets-leakcovers: pii
test_endpointtest_input_scannertest_output_scannertest_canary_tokenscheck_fieldcheck_canarycheckScannerscannerScannerRegistryScanModel

Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).

OWASP Top 10 for LLM Applications
⚠LLM03Supply Chaincritical
Vulnerable/compromised dependencies, models or archives in the artifact.
•Dependency manifest — 15 pip requirements declared · deadbits-vigil-llm-f2b4c13/requirements.txtrisk surface
•Vulnerable dependencies — 156 known vulnerabilities in: flask@3.0.0, nltk@3.8.1, pyarrow@14.0.1, pydantic@1.10.7, streamlit@1.26.0, transformers@4.36.0, aiohttp@3.9.5, fastapi@0.99.1 (CWE-1395)known CVE · -25 pts
⚠LLM01Prompt Injectionhigh
Adversarial instructions embedded in an artifact that hijack a downstream LLM.
•Prompt-injection phrasing — instruction-subversion language detected · deadbits-vigil-llm-f2b4c13/README.md (CWE-77)expected
⚠LLM05Improper Output Handlinghigh
Code that pipes model/user output into shell, eval, SQL or paths unsafely.
•Suspicious code patterns — destructive rm -rf / · deadbits-vigil-llm-f2b4c13/Dockerfile (CWE-78)expected
⚠LLM06Excessive Agencyhigh
Over-broad tool/permission surface or unrestricted egress.
•External endpoints declared — 3 distinct host(s) · deadbits-vigil-llm-f2b4c13/.gitignoreexpected
•External endpoints declared — 1 distinct host(s) · deadbits-vigil-llm-f2b4c13/CONTRIBUTING.mdexpected
•External endpoints declared — 2 distinct host(s) · deadbits-vigil-llm-f2b4c13/Dockerfileexpected
•Egress to a private/loopback host — 127.0.0.1 · deadbits-vigil-llm-f2b4c13/README.md (CWE-918)expected
•External endpoints declared — 14 distinct host(s) · deadbits-vigil-llm-f2b4c13/README.mdexpected
§LLM09MisinformationGovernance
Artifacts designed to produce false/deceptive output.
Detectable only by runtime behavioral evaluation; addressed via responsible-use attestation.
◷LLM10Unbounded ConsumptionRuntime-enforced
Unbounded loops/recursion causing DoS or runaway cost.
Enforced at runtime by the gateway (rate limits + spend caps + size caps); static check flags unbounded loops.
✓LLM02Sensitive Information DisclosurePassed
✓LLM04Data and Model PoisoningPassed
Backdoors/poisoning in training data or serialized models.
Behavioral poisoning needs model execution; static check covers unsafe serialization + dataset skew only.
✓LLM07System Prompt LeakagePassed
✓LLM08Vector and Embedding WeaknessesPassed
PII or plaintext source leakage in embedding/vector exports.
Embedding inversion/poisoning is largely runtime; static check covers PII in vector exports.
OWASP Machine Learning Security Top 10
⚠ML06AI Supply Chaincritical
Compromised PyPI/npm packages, typosquats, unsafe serialized models.
•Dependency manifest — 15 pip requirements declared · deadbits-vigil-llm-f2b4c13/requirements.txtrisk surface
•Vulnerable dependencies — 156 known vulnerabilities in: flask@3.0.0, nltk@3.8.1, pyarrow@14.0.1, pydantic@1.10.7, streamlit@1.26.0, transformers@4.36.0, aiohttp@3.9.5, fastapi@0.99.1 (CWE-1395)known CVE · -25 pts
⚠ML02Data Poisoninghigh
Poisoned training datasets with triggers or anomalous distributions.
Static check covers trigger phrasing, PII and label skew; full poisoning detection is runtime.
•Prompt-injection phrasing — instruction-subversion language detected · deadbits-vigil-llm-f2b4c13/README.md (CWE-77)expected
⚠ML09Output Integrityhigh
Middleware tampering with model outputs in transit.
Gateway enforces TLS + response integrity; static check flags output-rewriting code.
•Suspicious code patterns — destructive rm -rf / · deadbits-vigil-llm-f2b4c13/Dockerfile (CWE-78)expected
§ML01Input Manipulation (Adversarial)Governance
Models vulnerable to adversarial perturbations.
Requires runtime robustness evaluation; addressed via publisher robustness attestation.
§ML03Model InversionGovernance
Training data reconstructable from a model's outputs.
Runtime/evaluation property; addressed via model-card data-provenance + DP attestation.
§ML04Membership InferenceGovernance
Determining whether a record was in the training set.
Runtime/evaluation property; addressed via overfitting disclosure + DP attestation.
§ML08Model SkewingGovernance
Models trained on skewed data producing biased output.
Requires fairness evaluation; addressed via model-card bias/limitations disclosure.
✓ML05Model TheftPassed
Unlicensed re-distribution / license-incompatible derivatives.
Static check verifies license declaration; extraction throttling is runtime.
✓ML07Transfer Learning AttackPassed
Backdoored base models / LoRA adapters propagating to derivatives.
Backdoor detection needs behavioral probing; static check covers unsafe serialization + provenance.
✓ML10Model Poisoning (Weights)Passed
Tampered model weight files; integrity must be verifiable.
Static check enforces safe formats + records a content hash for downstream verification.
Other findings (8) · hygiene / uncategorized
•Unrecognized file type — '.gitignore' is not on the allowlist · deadbits-vigil-llm-f2b4c13/.gitignorerisk surface
•Unrecognized file type — '.?' is not on the allowlist · deadbits-vigil-llm-f2b4c13/Dockerfilerisk surface
•Suspicious network references — suspicious TLD (2 URLs) · deadbits-vigil-llm-f2b4c13/Dockerfileexpected
•Suspicious network references — raw IP URL (28 URLs) · deadbits-vigil-llm-f2b4c13/README.mdexpected
•Unrecognized file type — '.conf' is not on the allowlist · deadbits-vigil-llm-f2b4c13/conf/docker.confrisk surface
•Unrecognized file type — '.regex' is not on the allowlist · deadbits-vigil-llm-f2b4c13/data/regex/pattern.regexrisk surface
•Unrecognized file type — '.yar' is not on the allowlist · deadbits-vigil-llm-f2b4c13/data/yara/apitokens.yarrisk surface
•Suspicious network references — raw IP URL (1 URLs) · deadbits-vigil-llm-f2b4c13/scripts/test_api.shexpected
✔ verified source · pinned deadbits-vigil-llm-f2b4c13
Check against a policy

The same gate an agent runs before installing (POST /api/v1/trust/vigil-llm-prompt-injection-scanner/check). Click a policy:

Consume Vigil programmatically. Authenticate with an API key or session — see Authorize an agent.

# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/vigil-llm-prompt-injection-scanner

# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/vigil-llm-prompt-injection-scanner/check \
  -H "Content-Type: application/json" \
  -d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'

# CLI
npx ai-supply add vigil-llm-prompt-injection-scanner

# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/vigil-llm-prompt-injection-scanner/install \
  -H "Authorization: Bearer $AIM_KEY"

# MCP tool
install_listing({ "slug": "vigil-llm-prompt-injection-scanner" })
OpenAPI spec →
vlatest
! Security: Review · 751mo ago

Curated mirror — latest upstream source. See the repository for tagged releases.

Sign in and install this listing to leave a review.

More from @ai-supply

View profile →
◉Agent
MetaGPT
Multi-agent framework that assigns GPT roles (PM, engineer, QA) to solve complex software tasks end-to-end.
↓ 1.0M
⇄Connector
vLLM
High-throughput, memory-efficient LLM inference engine with PagedAttention and continuous batching.
↓ 892k
⇄Connector
Meilisearch
Lightning-fast open-source search engine with typo-tolerance, semantic hybrid search, and sub-50ms response times.
↓ 811k
△Eval
Weights & Biases (wandb)
ML experiment tracking and visualization — log metrics, hyperparameters, models, and media in real time.
↓ 784k
ai-supply.store

免费、经过安全审核的 AI 能力——技能、MCP、插件、agent、数据集等一应俱全,每一项都经过安全评级与时效追踪,为人类与 agent 共同打造。

api · v3.1status · all green
联系
support@ai-supply.storesecurity@ai-supply.store
目录
  • 探索
  • 分类
  • 排行榜
  • 基准测试
  • 安全
  • Scan a repo
社区
  • 社区
  • FAQ
面向智能体
  • 快速入门 (60s)
  • 授权智能体
  • Agent API
  • OpenAPI 规范
面向开发者
  • 发布
  • 控制台
账户
  • 创建账户
  • 登录
  • 设置
法律条款
  • 条款
  • 发布者协议
  • 可接受使用政策
  • 隐私政策