Skip to main content

Pencheff Sentry

Runtime LLM guardrail. Sits between your application and the model provider (or as a LiteLLM plugin / MCP middleware) and blocks prompt injection, PII exfiltration, secret leakage, and tool-authz violations as they happen — instead of catching them post-hoc on a Pencheff scan.

Sentry reuses the same detector library as the Pencheff red-team scanner. Anything the scanner finds offline, Sentry blocks online, with the same OWASP-LLM-Top-10 taxonomy.

Modes

Mode What it is When to use
HTTP proxy sidecar A FastAPI service in front of your LLM endpoint OpenAI-compatible providers; drop-in URL change
LiteLLM plugin A pre_call / post_call hook Existing LiteLLM stack; one-line install
MCP middleware Wraps the MCP tool-call path LLM agents calling tools; blocks unsafe tool args inline

The default judge is IBM Granite Guardian (Apache-2.0). Llama Guard 3 is opt-in and requires PENCHEFF_LLAMA_GUARD_ENABLED=1 per the Llama Community License (≤700 M MAU + attribution).

Quick start (HTTP proxy)

pip install pencheff-sentry

pencheff-sentry serve \
    --upstream https://api.openai.com/v1 \
    --port 4242 \
    --judge openai-moderation \
    --judge-endpoint https://api.openai.com/v1/moderations

Point your application at http://localhost:4242 instead of the upstream URL. Requests/responses flow through the detector chain; unsafe ones are blocked with a 403 Sentry: <reason> and logged to the configured sink.

What it blocks

Category Detector
LLM01 — Prompt injection Regex + judge ensemble
LLM02 — Sensitive info disclosure PII regex (SSN, card, email, phone) + judge
LLM05 — Improper output handling XSS / <script> / iframe in model output
LLM06 — Excessive agency Tool-call argument inspection (MCP middleware mode)
LLM10 — Unbounded consumption Token / latency / cost ceilings

The full detector list is configurable per-deployment via config.yaml.

License

MIT. See LICENSE at the Pencheff repo root.

Metadata

Release files for pencheff-sentry 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pencheff-sentry 0.1.0
File Size Uploaded
pencheff_sentry-0.1.0.tar.gz 11.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pencheff-sentry 0.1.0
File Interpreter ABI Platform
pencheff_sentry-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.0 kB

Release files / pencheff_sentry-0.1.0.tar.gz

Download URL pencheff_sentry-0.1.0.tar.gz
Size 11.6 kB
Tags Source
SHA-256 checksum
How to use checksums
15c0b6afe591077e7adf479d2b994d59b7708678a66ff7965787db7021e1ce61
BLAKE2b-256 checksum
How to use checksums
5ebba4779c856f72eb09ed6c2df326581070fdd62600855b15bf8fc8bddc54f2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.3

Release files / pencheff_sentry-0.1.0-py3-none-any.whl

Download URL pencheff_sentry-0.1.0-py3-none-any.whl
Size 12.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b97c464d59a204b7d6130b0cae793a4158356ce3753df2e9ca4763191258c222
BLAKE2b-256 checksum
How to use checksums
d4683dc370280d39bb0d0b991e49bcff37adf39f33acb867adffd21e205b8ae4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.3

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page