@benchspan/sdk
v0.3.1
Published
Prompt injection firewall for LLM agents. Scan tool outputs and user messages before they reach your model.
Maintainers
Readme
@benchspan/sdk
Prompt injection firewall for LLM agents. One-line integration that scans tool outputs and user messages before they reach your model.
Install
npm install @benchspan/sdkQuick Start
import { BenchGuard } from "@benchspan/sdk";
const guard = new BenchGuard({ apiKey: "ag_live_...", agent: "my-agent" });
// Direct scan
const result = await guard.scan("some tool output", { role: "tool" });
// result.injection -> true/false
// result.verdict -> "block" | "warn" | "pass"Framework Integrations
Vercel AI SDK
import { BenchGuard } from "@benchspan/sdk";
import { wrapLanguageModel, generateText } from "ai";
import { anthropic } from "@ai-sdk/anthropic";
const guard = new BenchGuard({ apiKey: "ag_live_..." });
const model = wrapLanguageModel({
model: anthropic("claude-sonnet-4-6"),
middleware: guard.asMiddleware(),
});
const { text } = await generateText({ model, prompt: "Hello" });LangChain JS
import { BenchGuard } from "@benchspan/sdk";
import { ChatAnthropic } from "@langchain/anthropic";
const guard = new BenchGuard({ apiKey: "ag_live_..." });
const llm = new ChatAnthropic({ model: "claude-sonnet-4-6" });
const result = await llm.invoke(messages, { callbacks: [guard.asLangChainCallback()] });OpenAI Agents SDK
import { BenchGuard } from "@benchspan/sdk";
const guard = new BenchGuard({ apiKey: "ag_live_..." });
const agent = new Agent({
name: "assistant",
model: "gpt-4o",
hooks: guard.asAgentHooks(),
});Google ADK
import { BenchGuard } from "@benchspan/sdk";
import { LlmAgent } from "@google/adk";
const guard = new BenchGuard({ apiKey: "ag_live_..." });
const agent = new LlmAgent({
name: "assistant",
model: "gemini-2.5-pro",
beforeModelCallback: guard.asAdkCallback(),
});Raw OpenAI / Anthropic SDK
import { BenchGuard } from "@benchspan/sdk";
import Anthropic from "@anthropic-ai/sdk";
const guard = new BenchGuard({ apiKey: "ag_live_..." });
const client = new Anthropic();
const result = await guard.wrapCall(messages, () =>
client.messages.create({ model: "claude-sonnet-4-6", messages })
);Modes
"block"(default) -- Waits for scan result. ThrowsInjectionDetectedErrorif injection detected."warn"-- Fires scan in the background with zero added latency. Logs a warning if injection detected but never blocks.
// Production -- block injections
const guard = new BenchGuard({ apiKey: "ag_live_...", mode: "block" });
// Evaluation -- monitor without blocking
const guard = new BenchGuard({ apiKey: "ag_live_...", mode: "warn" });How It Works
- Framework hook fires before each LLM call
- SDK scans
userandtoolmessages via the BenchSpan API systemandassistantmessages are skipped (trusted)- Already-scanned messages are deduplicated across multi-turn conversations
- In block mode,
InjectionDetectedErroris thrown if injection detected - In warn mode, the scan runs async -- zero latency added to your agent
