Skip to main content

Universal outbound data guard for AI agents — regex-first NER pipeline, zero ML weight, runs everywhere.

Project description

Safeclaw

Universal outbound data guard for AI agents.

Safeclaw catches sensitive data (API keys, passwords, emails, credit cards) before an AI agent accidentally leaks it. Runs on-premise with zero external calls — works for local dev, CI/CD pipelines, and enterprise deployments alike.

pip install safeclaw-guard

Why This Exists

AI agents have access to your codebase, .env files, databases, and configs. When they generate output — a shell command, a file, an API call — they can accidentally include secrets in plaintext. The agent doesn't know it's leaking. Safeclaw stops that at the exit.

Safeclaw flow diagram

In plain English: The AI agent reads your secrets to do its job. Safeclaw makes sure those secrets don't appear in the output.

Block vs Redact

Input:  "Deploy with key sk-ant-api03-realkey123..."
Output: "[SAFECLAW BLOCKED] contains sensitive data: Anthropic API Key"

Input:  "Send report to john@acme.com and call 555-867-5309"
Output: "Send report to [REDACTED:EMAIL] and call [REDACTED:PHONE]"

Configurable per entity type — API keys block, emails redact. Your call.


Get Started

Claude Code (1 command)

pip install safeclaw-guard
safeclaw install

Every tool call is now auto-scanned.

Python library

from safeclaw import guard

result = guard("Contact john@acme.com with key sk-ant-api03-abc123...")
print(result.safe)      # False
print(result.blocked)   # True — API key detected
print(result.text)      # [SAFECLAW BLOCKED] ...

HTTP server (any language)

safeclaw serve   # starts on localhost:18791
curl -X POST http://127.0.0.1:18791/scan \
  -H "X-Safeclaw-Secret: <secret>" \
  -d '{"text": "your text here"}'

MCP server (any MCP-compatible agent)

safeclaw install --mcp

What It Detects

Entity Default Examples
API Keys 🔴 Block sk-ant-..., AKIA..., ghp_..., sk_live_...
Private Keys 🔴 Block PEM-encoded RSA/EC keys
Passwords 🔴 Block password = "...", postgres://user:pass@host
Credit Cards 🔴 Block Visa, Mastercard, Amex (Luhn-validated)
SSNs 🔴 Block 123-45-6789
JWTs 🟡 Redact eyJhbG... base64 tokens
Emails 🟡 Redact user@domain.com
Phone Numbers 🟡 Redact US and international formats

Architecture

Safeclaw architecture diagram

  • Pipeline pattern (spaCy/sklearn-inspired) — pluggable detectors. Ships with RegexDetector, drop in an ML model later without changing any code.
  • Pydantic v2 models — typed Span, Entity, GuardResult following NER conventions.
  • Confidence scoring — every match has a score (0.0–1.0). Only flags above your threshold.
  • Overlap resolution — when two patterns match the same span, highest confidence wins.

Configuration

safeclaw init    # creates .safeclaw.yaml
threshold: 0.75       # confidence cutoff
fail_open: true       # if error: pass through (true) or block (false)

rules:
  api_key:    { action: block,  enabled: true }
  email:      { action: redact, enabled: true }
  phone:      { action: redact, enabled: true }
  ip_address: { action: redact, enabled: false }  # too noisy

Commands

Command What it does
safeclaw scan Scan stdin (also works as Claude Code hook)
safeclaw serve HTTP server on localhost
safeclaw mcp MCP stdio server
safeclaw install Add to Claude Code
safeclaw uninstall Remove from Claude Code
safeclaw init Create config file

Try It

git clone https://github.com/wassupjay/SafeClaw.git && cd SafeClaw
python -m venv .venv && source .venv/bin/activate
pip install -e .
python demo.py
Demo output
  Clean text          → ✅ PASS
  Email               → 🟡 REDACT  [REDACTED:EMAIL]
  Phone               → 🟡 REDACT  [REDACTED:PHONE]
  JWT                 → 🟡 REDACT  [REDACTED:JWT]
  OpenAI key          → 🔴 BLOCK
  Anthropic key       → 🔴 BLOCK
  AWS key             → 🔴 BLOCK
  GitHub token        → 🔴 BLOCK
  Stripe key          → 🔴 BLOCK
  Password            → 🔴 BLOCK
  Credentials in URL  → 🔴 BLOCK
  SSN                 → 🔴 BLOCK
  Credit card         → 🔴 BLOCK
  PEM private key     → 🔴 BLOCK
  16/16 tests passed

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

safeclaw_guard-0.1.1.tar.gz (70.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

safeclaw_guard-0.1.1-py3-none-any.whl (20.6 kB view details)

Uploaded Python 3

File details

Details for the file safeclaw_guard-0.1.1.tar.gz.

File metadata

  • Download URL: safeclaw_guard-0.1.1.tar.gz
  • Upload date:
  • Size: 70.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for safeclaw_guard-0.1.1.tar.gz
Algorithm Hash digest
SHA256 30aef29e46bdf260bd43d7fa4c823e63fe02d946dcdeebff9fe6fcdda14a14b7
MD5 9eb9363a6a7b4087af8401bc229c28c3
BLAKE2b-256 36dac162d63371216d8da72e4df9c0782a44f887ab9fb53dfe4a636d4463550d

See more details on using hashes here.

File details

Details for the file safeclaw_guard-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: safeclaw_guard-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 20.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for safeclaw_guard-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 35c459db48aa5c8cdd4fea1c0ed1f915fe2633bd8df234899f4d1c00c75ea243
MD5 5b0b34553c10b8bac33b7ede153f8c2e
BLAKE2b-256 052dcd57a2b8596c9f80e0b5ffa170e5261f11d1698e9b7c19d612e9f19e3bda

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page