-
Notifications
You must be signed in to change notification settings - Fork 0
Home
AISRF (AI Security & Research Framework, package aisrf, release v1.0.0) is a human-in-the-loop gateway that sits between LLM-powered applications or autonomous agents and the model providers or enterprise APIs they call. Every outbound request becomes a ticket. A ticket is analyzed, scored, run through a policy engine and, unless policy decides on its own, parked until a reviewer approves or denies it. Around that gate the project adds guardrail integrations, a red-team engine that drives its own probe corpus and external scanners through the same pipeline, static analysis of LLM application source code, reports in 13 formats, and an MCP server that exposes every reviewer action to AI assistants.
Source: https://github.com/keyuraghao/aisrf. License: Apache-2.0.
Nothing reaches the upstream without a decision. In aisrf/gateway/router.py the only path to the forwarder is through a ticket whose status is APPROVED, either because a reviewer approved it or because the agent's policy returned approve. Tickets that are DENIED (by policy or by a reviewer) or EXPIRED (no decision before AISRF_APPROVAL_TIMEOUT_SECONDS) are answered with an error and are never forwarded, and only PENDING tickets can be decided, so a ticket that expired cannot be approved afterwards. The client never holds the provider credential: the gateway strips the client's auth headers and injects the agent's Fernet-encrypted upstream key at forward time.
| Page | What it covers |
|---|---|
| Getting-Started | Install from source, first run, first agent, first approved ticket, async mode |
| Installation | Binaries, pip, Docker, Helm, service installs |
| Core-Concepts | Agents, tickets and statuses, risk, findings, policy, reviewers, scan tokens, canaries, campaigns |
| Glossary | Short definitions of every term |
| FAQ | Common questions |
| Page | What it covers |
|---|---|
| Architecture | Components, process model, data model, code layout |
| Gateway-Endpoints-and-Headers |
/v1/{path}, /proxy/{path}, /gateway/tickets/{id}, every header and error body |
| Request-Normalization | What the parser understands and the normalized structure |
| Policy-Engine | Evaluation order, every rule, response withholding |
| Agents-and-Credentials | Every agent field, key rotation, upstream providers |
| Integrations-and-SDKs | Python SDK, Node package, mitmproxy addon, LangChain, curl |
| Page | What it covers |
|---|---|
| Tickets-and-Review-Workflow | Queue, ticket detail, decisions, bulk actions, keyboard shortcuts, expiry |
| Dashboard-Guide | Every dashboard page |
| Notifications | Slack and generic webhooks |
| Reports | Report types and the 13 output formats |
| Page | What it covers |
|---|---|
| Analyzers | Request and response analyzers |
| Taxonomy-and-OWASP-Mapping | OWASP LLM Top 10, Greshake and Thacker mappings |
| Guardrails | LLM Guard, NeMo Guardrails, Lakera, Rebuff |
| TypeSafe-Integration | TypeSafe (Jev) decision layer: verdicts, confidence-gated escalation and routing, red-team and code review triage |
| Canary-Words | Canary injection and leak detection |
| Custom-Rules | Regex rules with flag or deny actions |
| Page | What it covers |
|---|---|
| Red-Teaming | Campaigns, mutators, evaluators |
| Probe-Corpus | The probe corpus and its categories |
| Comparison-Groups | Same probes against several models |
| Scanner-Engines | garak, promptfoo, PyRIT, PyRIT-Ship |
| Code-Review | Static analysis of LLM application code |
| Code-Review-Rules | The rule packs |
| Page | What it covers |
|---|---|
| Configuration-Reference | Every AISRF_* setting and every settings namespace |
| Settings-Center | The dashboard settings page, section by section |
| Logging-Metrics-and-Audit | Log files, event names, SSE streams, Prometheus metrics, audit chain |
| Security-Model | Threat model, secrets handling, roles, hardening checklist |
| Deployment | Compose, Postgres, TLS, Kubernetes |
| Desktop-Mode | aisrf desktop |
| Operations-and-Maintenance | Backups, retention, upgrades |
| Troubleshooting | Symptoms and fixes |
| Page | What it covers |
|---|---|
| REST-API-Reference | Every endpoint |
| MCP-Server | MCP tools over streamable HTTP and stdio |
| CLI-Reference | Every aisrf command |
| Page | What it covers |
|---|---|
| Development-Guide | Repository layout, conventions, adding analyzers |
| Testing | Running the test suite |
| Releasing | Tagging and the release workflow |
-
Clone and install into a virtual environment, then start the server (about two minutes):
git clone https://github.com/keyuraghao/aisrf.git && cd aisrf uv venv .venv && uv pip install --python .venv/bin/python -e ".[dev]" .venv/bin/aisrf serve
-
Open http://localhost:8080 and sign in with
admin/admin(the bootstrap account fromAISRF_ADMIN_USERNAMEandAISRF_ADMIN_PASSWORD). -
Create an agent under Agents, paste your provider key as the upstream key, and copy the
aisrf_...agent key. It is shown once. -
Point a client at the gateway:
from openai import OpenAI client = OpenAI(base_url="http://localhost:8080/v1", api_key="aisrf_...", timeout=330, max_retries=0) client.chat.completions.create(model="gpt-4o-mini", messages=[{"role": "user", "content": "hello"}])
-
The call blocks. A ticket appears in the queue at
/ticketswith its risk score and findings. Pressato approve it. The response arrives at the client with anX-AISRF-Ticketheader. -
Open
/auditto see the hash-chained record of your decision.
The full walkthrough, including the asynchronous mode and the files the first run creates, is in Getting-Started.
- This wiki, starting with FAQ and Troubleshooting.
- The interactive API documentation served by every instance at
/api/docs(Swagger UI),/api/redocand/api/openapi.json. - The
docs/directory of the repository, which holds the architecture, API, configuration, deployment, integrations, guardrails, red team, scanners, code review, reports, MCP and security documents. - Every CLI command answers
--help. - Issues and discussions on GitHub: https://github.com/keyuraghao/aisrf/issues. Security reports follow the process in the repository's top-level
SECURITY.md.
AISRF, AI Security & Research Framework. github.com/keyuraghao/aisrf, Apache License 2.0.
Start
Gateway
- Gateway-Endpoints-and-Headers
- Request-Normalization
- Policy-Engine
- Agents-and-Credentials
- Configuration-Reference
- Settings-Center
Review
Security analysis
Red teaming
Code review
Interfaces
Operations
Project