@axiorank/detectors
v0.2.1
Published
AxioRank content-inspection engine: detectors + risk scoring for AI agent tool calls. Catches secrets, prompt injection, PII, destructive ops, egress, malware and crypto/financial identifiers. Pure, universal, zero runtime dependencies.
Maintainers
Readme
@axiorank/detectors
The AxioRank content-inspection engine. Pure, universal, and dependency-free: it reads a tool call (a name plus arguments) and returns the risk signals it finds, plus a copy of the payload with secrets masked in place.
It detects leaked secrets, prompt injection, PII, destructive operations, and
egress attempts, and is the single source of truth shared by the AxioRank hosted
gateway, the SDK's local inspect(), and mcpaudit.
npm install @axiorank/detectorsimport { scoreToolCall, localDecision } from "@axiorank/detectors";
const scored = scoreToolCall("db.query", {
sql: "DROP TABLE users; -- ignore previous instructions",
});
const verdict = localDecision(scored.score, scored.signals);
console.log(verdict.decision); // "deny"
console.log(scored.signals.map((s) => s.detector));The universal entry runs in Node, edge, and the browser. @axiorank/detectors/node
adds a salted fingerprint and recursive base64/hex/gzip decoding for Node.
Detection is identical to the AxioRank gateway. AxioRank adds runtime enforcement, approvals, and a tamper-evident audit log on top.
License
MIT
