PromptGate / README.md
NagaYu's picture
PromptGate v1.0.0: rule pack running client-side via Pyodide
91c5efa verified
|
Raw History Blame Contribute Delete
2.25 kB
metadata
title: PromptGate
emoji: 🛡️
colorFrom: indigo
colorTo: gray
sdk: static
app_file: index.html
pinned: false
license: apache-2.0
short_description: Prompt injection, PII and secret detection in your browser
tags:
  - prompt-injection
  - llm-security
  - guardrails
  - pii-detection
  - pyodide

PromptGate

Screens prompts for injection, PII and leaked credentials before they reach an LLM. Deterministic rules, no model weights.

This Space runs the real detector in your browser. The same promptgate_rules.py and rules.json published in NagaYu/promptgate-rules are executed client-side through Pyodide. There is no server and no inference call, so nothing you type leaves your machine. The first load fetches the Python runtime (~10 MB); after that every check takes a few milliseconds and works offline.

Measured results

70 held-out cases, written after the rules were frozen and evaluated once:

Metric Result
Exact verdict accuracy 61.4 %
PII / secret prompts correctly redacted 83.3 %
Benign prompts wrongly flagged 11.1 %
Injection attacks correctly blocked 25.0 %

Credentials and PII have fixed shapes, so patterns transfer to unseen text. Prompt injection is semantic, and paraphrases walk straight past a pattern list. Treat this as a cheap deterministic first layer and a redaction tool, not as an injection defense. Every individual miss is listed in the benchmark card.

The full gateway

This page demonstrates the safety engine. The complete PromptGate gateway also does token-budget compression, JSON extraction and repair, an observability dashboard and a REST API. It is a Gradio app (app.py) that runs anywhere Python does:

pip install gradio huggingface_hub pandas
python app.py

Hosting it as a Gradio Space requires a paid tier, which is why the public demo here is static.

Project

Apache-2.0. One layer of defense, not a safety guarantee.