Skip to main content

Universal outbound data guard for AI agents — regex-first NER pipeline, zero ML weight, runs everywhere.

Project description

Safeclaw

Universal outbound data guard for AI agents.

Safeclaw catches sensitive data (API keys, passwords, emails, credit cards) before an AI agent accidentally leaks it. Runs on-premise with zero external calls — works for local dev, CI/CD pipelines, and enterprise deployments alike.

pip install safeclaw-guard

Why This Exists

AI agents have access to your codebase, .env files, databases, and configs. When they generate output — a shell command, a file, an API call — they can accidentally include secrets in plaintext. The agent doesn't know it's leaking. Safeclaw stops that at the exit.

flowchart LR
    ENV["Your secrets\n.env files, API keys\npasswords, customer data"]
    AGENT["AI Agent\nClaude Code, Cursor, etc."]
    SCAN["SAFECLAW\nscans outbound message"]
    PASS["Pass through"]
    REDACT["Redact PII"]
    BLOCK["Block secrets"]
    OUT["Outside world\nterminal, files, APIs"]

    ENV --> AGENT
    AGENT --> SCAN
    SCAN -- clean --> PASS
    SCAN -- email, phone --> REDACT
    SCAN -- API key, password --> BLOCK
    PASS --> OUT
    REDACT --> OUT

    style ENV fill:#6c757d,stroke:#333,color:#fff
    style AGENT fill:#4a90d9,stroke:#333,color:#fff
    style SCAN fill:#e8943a,stroke:#333,color:#fff
    style PASS fill:#5cb85c,stroke:#333,color:#fff
    style REDACT fill:#f0ad4e,stroke:#333,color:#fff
    style BLOCK fill:#d9534f,stroke:#333,color:#fff
    style OUT fill:#6c757d,stroke:#333,color:#fff

In plain English: The AI agent reads your secrets to do its job. Safeclaw makes sure those secrets don't appear in the output.

Block vs Redact

Input:  "Deploy with key sk-ant-api03-realkey123..."
Output: "[SAFECLAW BLOCKED] contains sensitive data: Anthropic API Key"

Input:  "Send report to john@acme.com and call 555-867-5309"
Output: "Send report to [REDACTED:EMAIL] and call [REDACTED:PHONE]"

Configurable per entity type — API keys block, emails redact. Your call.


Get Started

Claude Code (1 command)

pip install safeclaw-guard
safeclaw install

Every tool call is now auto-scanned.

Python library

from safeclaw import guard

result = guard("Contact john@acme.com with key sk-ant-api03-abc123...")
print(result.safe)      # False
print(result.blocked)   # True — API key detected
print(result.text)      # [SAFECLAW BLOCKED] ...

HTTP server (any language)

safeclaw serve   # starts on localhost:18791
curl -X POST http://127.0.0.1:18791/scan \
  -H "X-Safeclaw-Secret: <secret>" \
  -d '{"text": "your text here"}'

MCP server (any MCP-compatible agent)

safeclaw install --mcp

What It Detects

Entity Default Examples
API Keys 🔴 Block sk-ant-..., AKIA..., ghp_..., sk_live_...
Private Keys 🔴 Block PEM-encoded RSA/EC keys
Passwords 🔴 Block password = "...", postgres://user:pass@host
Credit Cards 🔴 Block Visa, Mastercard, Amex (Luhn-validated)
SSNs 🔴 Block 123-45-6789
JWTs 🟡 Redact eyJhbG... base64 tokens
Emails 🟡 Redact user@domain.com
Phone Numbers 🟡 Redact US and international formats

Architecture

graph TB
    subgraph "Safeclaw Core"
        P["Pipeline"]
        R["RegexDetector"]
        M["MLDetector (pluggable)"]
        P --> R
        P --> M
    end

    subgraph "Integration Layer"
        CLI["CLI (stdin/stdout)"]
        HOOK["Claude Code Hook"]
        MCP["MCP Server (stdio)"]
        HTTP["HTTP Server (FastAPI)"]
    end

    subgraph "Policy Engine"
        CFG["safeclaw.yaml config"]
        RED["Redactor"]
        GUARD["Guard"]
    end

    P --> GUARD
    CFG --> GUARD
    GUARD --> RED

    CLI --> P
    HOOK --> P
    MCP --> P
    HTTP --> P

    style P fill:#4a90d9,stroke:#333,color:#fff
    style R fill:#5cb85c,stroke:#333,color:#fff
    style M fill:#5cb85c,stroke:#333,color:#fff,stroke-dasharray: 5 5
    style GUARD fill:#e8943a,stroke:#333,color:#fff
  • Pipeline pattern (spaCy/sklearn-inspired) — pluggable detectors. Ships with RegexDetector, drop in an ML model later without changing any code.
  • Pydantic v2 models — typed Span, Entity, GuardResult following NER conventions.
  • Confidence scoring — every match has a score (0.0–1.0). Only flags above your threshold.
  • Overlap resolution — when two patterns match the same span, highest confidence wins.

Configuration

safeclaw init    # creates .safeclaw.yaml
threshold: 0.75       # confidence cutoff
fail_open: true       # if error: pass through (true) or block (false)

rules:
  api_key:    { action: block,  enabled: true }
  email:      { action: redact, enabled: true }
  phone:      { action: redact, enabled: true }
  ip_address: { action: redact, enabled: false }  # too noisy

Commands

Command What it does
safeclaw scan Scan stdin (also works as Claude Code hook)
safeclaw serve HTTP server on localhost
safeclaw mcp MCP stdio server
safeclaw install Add to Claude Code
safeclaw uninstall Remove from Claude Code
safeclaw init Create config file

Try It

git clone https://github.com/wassupjay/SafeClaw.git && cd SafeClaw
python -m venv .venv && source .venv/bin/activate
pip install -e .
python demo.py
Demo output
  Clean text          → ✅ PASS
  Email               → 🟡 REDACT  [REDACTED:EMAIL]
  Phone               → 🟡 REDACT  [REDACTED:PHONE]
  JWT                 → 🟡 REDACT  [REDACTED:JWT]
  OpenAI key          → 🔴 BLOCK
  Anthropic key       → 🔴 BLOCK
  AWS key             → 🔴 BLOCK
  GitHub token        → 🔴 BLOCK
  Stripe key          → 🔴 BLOCK
  Password            → 🔴 BLOCK
  Credentials in URL  → 🔴 BLOCK
  SSN                 → 🔴 BLOCK
  Credit card         → 🔴 BLOCK
  PEM private key     → 🔴 BLOCK
  16/16 tests passed

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

safeclaw_guard-0.1.0.tar.gz (17.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

safeclaw_guard-0.1.0-py3-none-any.whl (21.1 kB view details)

Uploaded Python 3

File details

Details for the file safeclaw_guard-0.1.0.tar.gz.

File metadata

  • Download URL: safeclaw_guard-0.1.0.tar.gz
  • Upload date:
  • Size: 17.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for safeclaw_guard-0.1.0.tar.gz
Algorithm Hash digest
SHA256 2ea55304f4158ff61afa7e67dbe46105f25f8c02e4ca7d961cbbbef0fc97fc02
MD5 f52a6d6d24721aa15af41a2c78817c60
BLAKE2b-256 0f20e507430cf2804b67d96ad062beb3161c83599a7e5649dd6731d201ecdb49

See more details on using hashes here.

File details

Details for the file safeclaw_guard-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: safeclaw_guard-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 21.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for safeclaw_guard-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 875d8123dc5cf23f729d557161d99185bf5be134bef46bf62581e18a3ba74c81
MD5 b468674b7969c6b1a725a41641b0a44e
BLAKE2b-256 838eeb69036735e59652ae37285eedd35fa9df178bd782af7b48aa8ba2891758

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page