Repository navigation
2. Architecture
Requests pass through injection-pattern checks, semantic intent scoring, PII detection and masking, the model call, and response unmasking. Tool hooks restore tokens before tool execution and scan tool inputs and outputs.
initGuard(config) preloads the selected intent and PII pipelines. guard(config) uses those same model names. Pipelines are cached by task and model name. Import the same configuration object into both call sites; initialization does not set global configuration.
Models are cached under models relative to the application's working directory. Missing models can trigger remote downloads. Inference runs locally; the application's generative model may use a remote provider. Startup time, memory and latency depend on the chosen models and hardware.
PII tokens contain an opaque namespace. The default vault is in memory; external storage supports persistence and multiple workers. Vault token lookup supports recovery across model/tool turns.
Intent and PII checks run in the current middleware implementation. An empty intent map with the default threshold blocks requests. Pattern checks and model predictions can produce false positives and false negatives; evaluate on your own inputs.
Injection checks cover prompt text, every message part, history and documents. Semantic intent uses the prompt or all content in the final message. Guard tokenizer state is held outside user-provided context fields. Model metadata omits guard-generated prompt copies and classifier output. See 12.-Security-and-Operational-Errors for failure boundaries and 11.-Framework-Compatibility for supported integration paths.