This is a text classifier that uses local CPU to classify text as prompt injection or benign
883
Exposes API that uses local hugging face model to detect potentially malicious prompt injection. Should not be used as the sole line of defense, but as part of a comprehensive layered LLM security model.
Uses local only (doesn't call external APIs) protectai/deberta-v3-base-prompt-injection-v2 model...runs in embedded nodejs express server.
Source Code: https://github.com/mikemainguy/saferprompt
The underlying engine can also be embedded as a library in a nodejs/browser app (though it requires 300m of storage for the local model....so browser might be a bad idea.
NPM Module: https://www.npmjs.com/package/saferprompt?activeTab=versions
The container has two environment variables baked in via the Dockerfile:
| Variable | Default | Description |
|---|---|---|
LOCAL_MODELS_ONLY | true | When true, the app uses only the model baked into the image and makes no network requests to HuggingFace. Set to false if you want the app to fetch model updates at startup. |
PORT | 3000 | The port the Express server listens on inside the container. |
There is also an optional variable not set by default:
| Variable | Default | Description |
|---|---|---|
API_KEY | (empty) | When set, all requests to /api/detect must include a matching x-api-key header. When empty, the API is open (no auth). |
Use -e flags to override any variable when running the container:
# Run on port 8080 with API key authentication enabled
docker run -p 8080:8080 \
-e PORT=8080 \
-e API_KEY=my-secret-key \
saferprompt
Note: when you change PORT, update the -p mapping to match. The left side is the host port (your choice), the right side must match the container's PORT.
# Map host port 9090 to container port 8080
docker run -p 9090:8080 -e PORT=8080 saferprompt
.env fileYou can pass a file of environment variables instead of individual -e flags:
# Create an env file
echo "API_KEY=my-secret-key" > .env.docker
# Pass it to docker run
docker run -p 3000:3000 --env-file .env.docker saferprompt
# Health check (no API key)
curl -X POST http://localhost:3000/api/detect \
-H "Content-Type: application/json" \
-d '{"text": "hello"}'
# With API key
curl -X POST http://localhost:3000/api/detect \
-H "Content-Type: application/json" \
-H "x-api-key: my-secret-key" \
-d '{"text": "hello"}'
Expected response:
{
"label": "SAFE",
"score": 0.9998,
"isInjection": false,
"ms": 42
}
You can also open http://localhost:3000 in a browser to use the test UI.
Content type
Image
Digest
sha256:54d5c6a9e…
Size
1 GB
Last updated
6 months ago
docker pull michaelmainguy/saferprompt