horde-safety
Provides safety features used by the horde, especially to do with image generation.
Environment Variables
This library is made with the default AI Horde worker in mind, and relies on the environment variable AIWORKER_CACHE_HOME to establish isolation of the clip models on disk. If you do not want to rely on a horde specific folder structure, define HF_HOME to define where you'd prefer the models to be. If neither are defined, the default huggingface folder location for the system used, typically ~/.cache, depending on other environnement variables, see the official huggingface docs for more info.
Warning: If you use
AIWORKER_CACHE_HOME, other environment variables can and will be overridden, includingHF_HOMEand potentially any other related variables. UsingAIWORKER_CACHE_HOMEis explictly opting into the horde isolation scheme, which may not be suitable for other contexts and may lead to duplicate (and very large) models on disk. If you want to use this library outside of the horde, it is recommended to setHF_HOMEinstead.
Installing
Make sure pytorch is installed, preferably with CUDA/ROCM or other GPU support.
pip install horde_safety
Use
This library currently relies on clip_interrogator. The check_for_csam function requires an instance of clip_interrogator.Interrogator to be passed. You can pass in on yourself, or use the helper function get_interrogator_no_blip (note that calling this function immediately loads the CLIP model). Use the device parameter to choose the device to load to and use for interrogation. If you want to only use the CPU but have CUDA pytorch installed, use get_interrogator_no_blip(device="cpu").
import PIL.Image
from horde_safety.deep_danbooru_model import get_deep_danbooru_model
from horde_safety.interrogate import get_interrogator_no_blip
from horde_safety.nsfw_checker_class import NSFWChecker, NSFWResult
interrogator = get_interrogator_no_blip() # Will trigger a download if not on disk (~1.2 gb)
deep_danbooru_model = get_deep_danbooru_model() # Will trigger a download if not on disk (~614 mb)
nsfw_checker = NSFWChecker(
interrogator,
deep_danbooru_model, # Optional, significantly improves results for anime images
)
image: PIL.Image.Image = PIL.Image.open("image.jpg")
prompt: str | None = None # if this is an image generation, you can provide the prompt here
model_info: dict | None = None # if this is an image generation, you can provide the model info here
nsfw_result: NSFWResult | None = nsfw_checker.check_for_nsfw(image, prompt=prompt, model_info=model_info)
if nsfw_result is None:
print("No NSFW result (Did it fail to load the image?)")
exit(1)
if nsfw_result.is_anime:
print("Anime detected!")
if nsfw_result.is_nsfw:
print("NSFW detected!")
if nsfw_result.is_csam:
print("CSAM detected!")
exit(1)
If you reject a job as a horde worker for CSAM, you should report 'state': 'csam' in the generate submit payload.
Metadata
Release files for horde-safety 0.3.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| horde_safety-0.3.1.tar.gz | 72.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| horde_safety-0.3.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 124.7 kB
Release files / horde_safety-0.3.1.tar.gz
| Download URL | horde_safety-0.3.1.tar.gz |
|---|---|
| Size | 72.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
325fdb072d0ea2f225472f28784c1b5153fc376438ecff76d4f85c45164fcc3f
|
|
BLAKE2b-256 checksum How to use checksums |
2486b20724acc9d198ed8ceeb14378adcab8481b03a4e9c8b517f972ff3ba630
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / horde_safety-0.3.1-py3-none-any.whl
| Download URL | horde_safety-0.3.1-py3-none-any.whl |
|---|---|
| Size | 51.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
46924addef595cdc05dec2d9c196c37d608b6ca2db38349a66af25f96f286e9e
|
|
BLAKE2b-256 checksum How to use checksums |
15c46861641e30059b883d6a974fa81bf17811068f759a9843e2b3f8d04e08f4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log