Universal outbound data guard for AI agents — regex-first NER pipeline, zero ML weight, runs everywhere.
Project description
Safeclaw
Universal outbound data guard for AI agents.
Safeclaw catches sensitive data (API keys, passwords, emails, credit cards) before an AI agent accidentally leaks it. Runs on-premise with zero external calls — works for local dev, CI/CD pipelines, and enterprise deployments alike.
pip install safeclaw-guard
Why This Exists
AI agents have access to your codebase, .env files, databases, and configs. When they generate output — a shell command, a file, an API call — they can accidentally include secrets in plaintext. The agent doesn't know it's leaking. Safeclaw stops that at the exit.
In plain English: The AI agent reads your secrets to do its job. Safeclaw makes sure those secrets don't appear in the output.
Block vs Redact
Input: "Deploy with key sk-ant-api03-realkey123..."
Output: "[SAFECLAW BLOCKED] contains sensitive data: Anthropic API Key"
Input: "Send report to john@acme.com and call 555-867-5309"
Output: "Send report to [REDACTED:EMAIL] and call [REDACTED:PHONE]"
Configurable per entity type — API keys block, emails redact. Your call.
Get Started
Claude Code (1 command)
pip install safeclaw-guard
safeclaw install
Every tool call is now auto-scanned.
Python library
from safeclaw import guard
result = guard("Contact john@acme.com with key sk-ant-api03-abc123...")
print(result.safe) # False
print(result.blocked) # True — API key detected
print(result.text) # [SAFECLAW BLOCKED] ...
HTTP server (any language)
safeclaw serve # starts on localhost:18791
curl -X POST http://127.0.0.1:18791/scan \
-H "X-Safeclaw-Secret: <secret>" \
-d '{"text": "your text here"}'
MCP server (any MCP-compatible agent)
safeclaw install --mcp
What It Detects
| Entity | Default | Examples |
|---|---|---|
| API Keys | 🔴 Block | sk-ant-..., AKIA..., ghp_..., sk_live_... |
| Private Keys | 🔴 Block | PEM-encoded RSA/EC keys |
| Passwords | 🔴 Block | password = "...", postgres://user:pass@host |
| Credit Cards | 🔴 Block | Visa, Mastercard, Amex (Luhn-validated) |
| SSNs | 🔴 Block | 123-45-6789 |
| JWTs | 🟡 Redact | eyJhbG... base64 tokens |
| Emails | 🟡 Redact | user@domain.com |
| Phone Numbers | 🟡 Redact | US and international formats |
Architecture
- Pipeline pattern (spaCy/sklearn-inspired) — pluggable detectors. Ships with
RegexDetector, drop in an ML model later without changing any code. - Pydantic v2 models — typed
Span,Entity,GuardResultfollowing NER conventions. - Confidence scoring — every match has a score (0.0–1.0). Only flags above your threshold.
- Overlap resolution — when two patterns match the same span, highest confidence wins.
Configuration
safeclaw init # creates .safeclaw.yaml
threshold: 0.75 # confidence cutoff
fail_open: true # if error: pass through (true) or block (false)
rules:
api_key: { action: block, enabled: true }
email: { action: redact, enabled: true }
phone: { action: redact, enabled: true }
ip_address: { action: redact, enabled: false } # too noisy
Commands
| Command | What it does |
|---|---|
safeclaw scan |
Scan stdin (also works as Claude Code hook) |
safeclaw serve |
HTTP server on localhost |
safeclaw mcp |
MCP stdio server |
safeclaw install |
Add to Claude Code |
safeclaw uninstall |
Remove from Claude Code |
safeclaw init |
Create config file |
Try It
git clone https://github.com/wassupjay/SafeClaw.git && cd SafeClaw
python -m venv .venv && source .venv/bin/activate
pip install -e .
python demo.py
Demo output
Clean text → ✅ PASS
Email → 🟡 REDACT [REDACTED:EMAIL]
Phone → 🟡 REDACT [REDACTED:PHONE]
JWT → 🟡 REDACT [REDACTED:JWT]
OpenAI key → 🔴 BLOCK
Anthropic key → 🔴 BLOCK
AWS key → 🔴 BLOCK
GitHub token → 🔴 BLOCK
Stripe key → 🔴 BLOCK
Password → 🔴 BLOCK
Credentials in URL → 🔴 BLOCK
SSN → 🔴 BLOCK
Credit card → 🔴 BLOCK
PEM private key → 🔴 BLOCK
16/16 tests passed
License
MIT
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file safeclaw_guard-0.1.2.tar.gz.
File metadata
- Download URL: safeclaw_guard-0.1.2.tar.gz
- Upload date:
- Size: 70.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7bbfed5ee951ac9cad2e6ace62e81f3acbd98e0ab9a315aef36d599c877c79ca
|
|
| MD5 |
3464893b472d99c9d5aecd4cfa33cc1d
|
|
| BLAKE2b-256 |
0e889857a4bc5a670e2ba418e69c9f1dab2b5f1ed0414f358a9ca46b3205a90a
|
File details
Details for the file safeclaw_guard-0.1.2-py3-none-any.whl.
File metadata
- Download URL: safeclaw_guard-0.1.2-py3-none-any.whl
- Upload date:
- Size: 20.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f9656ebdb83f1201504234c5fea7497a17e6d1fff3829c7ce34189e7e6a9c58f
|
|
| MD5 |
7ec707b6ad992715c8cf4376b10e78af
|
|
| BLAKE2b-256 |
bfb56b46876161d1e6ed447ec544920c592c3cf60305dff30d2c237b5b3b042e
|