llamaindex-relayshield
LlamaIndex tools and a mandatory pre-execution gate for RelayShield's agentic-security endpoints — MCP server registry risk and AI-agent-sourced credential breach detection.
Install
pip install llamaindex-relayshield
Tools
from llama_index.core.agent.workflow import FunctionAgent
from llama_index.core.llms.openai import OpenAI
from llamaindex_relayshield import check_mcp_server_risk_tool, check_prompt_injection_breach_tool
agent = FunctionAgent(
tools=[check_mcp_server_risk_tool, check_prompt_injection_breach_tool],
llm=OpenAI(model="gpt-4o-mini"),
)
result = await agent.run(
"Is it safe to connect to the MCP server at https://mcp.example.com/sse? My RelayShield key is rs_live_..."
)
check_mcp_server_risk— flags known-malicious IOC matches, typosquat domains, and newly-registered domains hosting an MCP server, before an agent connects to or installs it.check_prompt_injection_breach— checks whether an email appears in RelayShield's stolen-session corpus with a suspected-agentic-source marker (a session/token exposure that shows signs of having been captured via a compromised AI agent).
Both tools take api_key as a call argument rather than reading it from the environment implicitly — a shared agent process can act safely on behalf of multiple callers with different RelayShield keys.
Get a key at api.relayshield.net/developers.
Mandatory gate
Most "AI agent security" checks are optional — the agent can call them, but nothing stops it skipping the call and taking the risky action anyway. The RelayShield gate is the other kind: enforced before a protected action (connecting to or installing an MCP server) can happen at all.
LlamaIndex has no dedicated pre-execution hook API like LangChain's wrap_tool_call or the OpenAI Agents SDK's @tool_input_guardrail. What it does have is call_tool() — a workflow step every built-in agent (FunctionAgent, ReActAgent, CodeActAgent) inherits unmodified from BaseWorkflowAgent. This package subclasses it:
from llamaindex_relayshield import RelayShieldGatedFunctionAgent
from llamaindex_relayshield import check_mcp_server_risk_tool
agent = RelayShieldGatedFunctionAgent(
tools=[connect_mcp_server_tool, check_mcp_server_risk_tool],
llm=OpenAI(model="gpt-4o-mini"),
# Names of tools this gate applies to -- everything else runs unmodified.
protected_tools={"connect_mcp_server"},
)
RelayShieldGatedReActAgent and RelayShieldGatedCodeActAgent are the same pattern for the other two built-in agent types.
Properties, all non-negotiable by design:
- A hook exception defaults to
defer(blocked, with an explanatory message), never silently toallow— a gate failure must not become a pass. - Bounded retry applies only to transient upstream failures (timeout/429/5xx) — auth failures, malformed responses, and payment-required states are terminal after one attempt.
- The gate logs the decision, reason codes, check version, target, and timestamp — never keys, payment proofs, or session material.
- Only tool names listed in
protected_toolsare gated; everything else passes straight through to normal execution.
A note on how this is implemented, since it's less standard than the other two integrations: overriding call_tool() on a subclass only works because the override re-applies LlamaIndex's @step decorator. Verified directly against the installed package — LlamaIndex's step registry only recognizes methods carrying the _step_config attribute that @step sets at definition time; an override without it would silently fail to register as a step at all, breaking every tool call in the agent, not just skipping the gate.
Same normalized policy as langchain-relayshield's RelayShieldMCPGateMiddleware, openai-agents-relayshield's relayshield_mcp_gate, and the original standalone reference implementation, relayshield-langchain-gate — ported rather than imported, so this package has no dependency on LangChain/LangGraph or the OpenAI Agents SDK.
License
MIT
Metadata
Release files for llamaindex-relayshield 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| llamaindex_relayshield-0.1.1.tar.gz | 11.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| llamaindex_relayshield-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.5 kB
Release files / llamaindex_relayshield-0.1.1.tar.gz
| Download URL | llamaindex_relayshield-0.1.1.tar.gz |
|---|---|
| Size | 11.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0c071b5c6c19e9071a251ddcf4df18e5791772856e0bd5586e902571821d9805
|
|
BLAKE2b-256 checksum How to use checksums |
65872280ebb4ccabd18d7941f01c37062b200a21bddf5dd771c5b90ada7f6fc4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / llamaindex_relayshield-0.1.1-py3-none-any.whl
| Download URL | llamaindex_relayshield-0.1.1-py3-none-any.whl |
|---|---|
| Size | 11.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b51355387e5825f23ecd0d8ff237c0237866ea5fe360a61396e74c4a4a9a07b0
|
|
BLAKE2b-256 checksum How to use checksums |
6a8c47d35803c4f3c178ced1aa2f84782c8f9db330fc820a89717029ce906161
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|