PromptGate / README.md
NagaYu's picture
PromptGate v1.0.0: rule pack running client-side via Pyodide
91c5efa verified
|
Raw History Blame Contribute Delete
2.25 kB
---
title: PromptGate
emoji: 🛡️
colorFrom: indigo
colorTo: gray
sdk: static
app_file: index.html
pinned: false
license: apache-2.0
short_description: Prompt injection, PII and secret detection in your browser
tags:
- prompt-injection
- llm-security
- guardrails
- pii-detection
- pyodide
---
# PromptGate
Screens prompts for injection, PII and leaked credentials before they reach an
LLM. Deterministic rules, no model weights.
**This Space runs the real detector in your browser.** The same
`promptgate_rules.py` and `rules.json` published in
[NagaYu/promptgate-rules](https://huggingface.co/NagaYu/promptgate-rules) are
executed client-side through Pyodide. There is no server and no inference call,
so nothing you type leaves your machine. The first load fetches the Python
runtime (~10 MB); after that every check takes a few milliseconds and works
offline.
## Measured results
70 held-out cases, written after the rules were frozen and evaluated once:
| Metric | Result |
| --- | --- |
| Exact verdict accuracy | 61.4 % |
| PII / secret prompts correctly redacted | 83.3 % |
| Benign prompts wrongly flagged | 11.1 % |
| Injection attacks correctly blocked | **25.0 %** |
Credentials and PII have fixed shapes, so patterns transfer to unseen text.
Prompt injection is semantic, and paraphrases walk straight past a pattern list.
Treat this as a cheap deterministic first layer and a redaction tool, not as an
injection defense. Every individual miss is listed in the
[benchmark card](https://huggingface.co/datasets/NagaYu/promptgate-eval).
## The full gateway
This page demonstrates the safety engine. The complete PromptGate gateway also
does token-budget compression, JSON extraction and repair, an observability
dashboard and a REST API. It is a Gradio app (`app.py`) that runs anywhere
Python does:
```bash
pip install gradio huggingface_hub pandas
python app.py
```
Hosting it as a Gradio Space requires a paid tier, which is why the public demo
here is static.
## Project
- Rule pack: [NagaYu/promptgate-rules](https://huggingface.co/NagaYu/promptgate-rules)
- Benchmark: [NagaYu/promptgate-eval](https://huggingface.co/datasets/NagaYu/promptgate-eval)
Apache-2.0. One layer of defense, not a safety guarantee.