Skip to main content

IntentSeal

A prompt-injection firewall for AI agents. IntentSeal inspects everything your agent reads (user messages, web pages, PDFs, Word files, emails, Markdown, HTML, API responses, OCR text, source code, images, retrieved RAG passages) before the model sees it, and checks every tool call before it runs. It keeps the agent inside the user's intent.

  • Detects and neutralises instruction override, role change, secret extraction, tool abuse, credential theft, context poisoning, multi-step jailbreaks, encoded instructions and indirect prompt injection. Every decision is labelled with the attack type.
  • Sees what the model sees: hidden text in PDFs and Word files, CSS-hidden HTML, HTML-only email parts, look-alike letters and encoded payloads (base64, hex, %-encoding, Unicode tags) are decoded and checked.
  • Rules decide, AI advises: fast structural rules and a local classifier first, an AI judge only when needed, and deterministic action rules (allow-lists, pinned fields, outbound secret scan, "did the user ask for this?") that a model can never override.
  • Any model provider: the SDK checks content and tools, not the model call, so it works with OpenAI, Anthropic, Gemini, Groq, Mistral, local models or anything else.

Status: alpha (0.1). APIs may change between minor versions.

Install

pip install intentseal                 # talks to an IntentSeal gateway (remote mode): small install
pip install "intentseal[embedded]"     # runs the engine in your process (PDF/Word/HTML extraction, classifier, OCR)
pip install "intentseal[langchain]"    # LangChain / LangGraph tool helper

Python 3.11+.

Quickstart (embedded)

intentseal init --agent my-agent --template research-assistant    # writes ~/.intentseal/policies/my-agent.yaml
intentseal init --list                                             # other templates (RAG, support, coding agent)

Add one provider key for the AI judge to ~/.intentseal/.env or your project's .env (GROQ_API_KEY, GEMINI_API_KEY, NVIDIA_API_KEY or OPENROUTER_API_KEY). Then:

from intentseal import Guard

guard = Guard("my-agent")

with guard.session(user_id="u-42", task=user_message):
    page = guard.inspect(html, source="web")                       # cleaned content, or a short safe notice
    doc = guard.inspect(pdf_bytes, source="pdf", filename="q3.pdf")  # raw bytes: hidden text is seen too

    @guard.tool()                                                  # arguments checked before it runs
    def send_message(to: str, subject: str, body: str): ...

    send_message(to="someone@elsewhere.example", subject="...", body="...")   # blocked: returns a notice

The policy (~/.intentseal/policies/my-agent.yaml) lists your agent's tools with their risk, allow-lists (recipients, domains, paths), pinned fields and the words that count as the user asking for an action. Any tool not listed is blocked in enforce mode; mode: monitor records everything and blocks nothing.

Remote mode (a shared gateway, Console, audit trail)

guard = Guard("my-agent", remote="https://intentseal.example.com", api_key=os.environ["INTENTSEAL_KEY"])

Same API; decisions come from the gateway, which also offers an OpenAI- and Anthropic-compatible LLM proxy (protect an agent by changing its base URL only), a Security Console (decisions, approvals, session replay, policy) and SIEM export.

RAG

Check files when you index them and passages when you retrieve them:

r = guard.inspect_result(open(path, "rb").read(), source="rag", filename=path)
if r.enforced.value in ("BLOCK", "ESCALATE"):
    quarantine(path)                                               # never enters the index
else:
    index(r.cleaned_content)

with guard.session(user_id=user.id, task=question):
    passages = [guard.inspect(c.text, source="rag") for c in retriever.search(question)]

LangChain / LangGraph

tools = guard.protect_tools([search_tool, email_tool])             # inputs checked, outputs inspected

Source, documentation, evaluation results and the gateway: https://github.com/sankalp2515/intentseal

Licensed under the Apache License 2.0.

Metadata

Release files for intentseal 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for intentseal 0.1.0
File Size Uploaded
intentseal-0.1.0.tar.gz 15.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for intentseal 0.1.0
File Interpreter ABI Platform
intentseal-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 30.1 kB

Release files / intentseal-0.1.0.tar.gz

Download URL intentseal-0.1.0.tar.gz
Size 15.2 kB
Tags Source
SHA-256 checksum
How to use checksums
9971cfca4983a4a431e56c50f2b7f3f31da21d97b7b7c6a4f07f67adca1a0525
BLAKE2b-256 checksum
How to use checksums
1d184748cccc30f30a802d036e77481e1ad6574f3a3cb7206904f3cb73acc41d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release files / intentseal-0.1.0-py3-none-any.whl

Download URL intentseal-0.1.0-py3-none-any.whl
Size 14.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e751ef9ab7a6c344ba8cbd1d09ab3346676f7d7e6692a6af3cd5b0500975b99b
BLAKE2b-256 checksum
How to use checksums
80c4ee3b56d8177feaffb875bcb1ee09c8320cadcac2867ba6b1171f9003f80e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page