{"_id":"@aegis-sdk/core","_rev":"5-7e54a0a7befa9e87a51e041bfca3ad29","name":"@aegis-sdk/core","dist-tags":{"latest":"0.5.0"},"versions":{"0.0.0":{"name":"@aegis-sdk/core","version":"0.0.0","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"license":"MIT","_id":"@aegis-sdk/core@0.0.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"homepage":"https://github.com/aegis-sdk/aegis#readme","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"dist":{"shasum":"9be37d4c4bea053373d7c640ea4b9c137a83e21f","tarball":"https://registry.npmjs.org/@aegis-sdk/core/-/core-0.0.0.tgz","fileCount":8,"integrity":"sha512-wECU7CrF8PIKbVQrSscVrUDQHajGX17lZG0R3Lv59Ca2HKOK9RTptModqUzczmyMO3ajToCn4HtMQDMTUuxDMQ==","signatures":[{"sig":"MEQCIDS2TbfqVwPURvl0ehfqkxs/AN1qN0HNQWb9fi0Ng1j9AiACh5tHgWdkJwkJpOlWb8KCK9406cpi6RDjsnkRvr5ODA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":321824},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-core-0.0.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/1469f42d77bf95b3e78695816e7cb79f/aegis-sdk-core-0.0.0.tgz","_integrity":"sha512-wECU7CrF8PIKbVQrSscVrUDQHajGX17lZG0R3Lv59Ca2HKOK9RTptModqUzczmyMO3ajToCn4HtMQDMTUuxDMQ==","repository":{"url":"git+https://github.com/aegis-sdk/aegis.git","type":"git","directory":"packages/core"},"_npmVersion":"10.9.4","description":"Streaming-first prompt injection defense for AI applications","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.0.0_1771367880074_0.7223331431739008","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@aegis-sdk/core","version":"0.1.0","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"license":"MIT","_id":"@aegis-sdk/core@0.1.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"homepage":"https://github.com/aegis-sdk/aegis#readme","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"dist":{"shasum":"a650261d74fa8d5e326b562fc386f18965a3ef1f","tarball":"https://registry.npmjs.org/@aegis-sdk/core/-/core-0.1.0.tgz","fileCount":8,"integrity":"sha512-jd7cZbjxEr6NmN/9medqa3bqm1mFbi6v4U7fb4lQy68yXtYF1kKy0tstPqkLoAIjRBOw1r5ELjX1rZmKhEdOww==","signatures":[{"sig":"MEQCIB04ZGyusLBOsr19FMK08HrH1ieHlXR8FnUb8463x+kgAiA8Y+nnkwPPlfBl0nDNiek6MBkBn0Uh7AllbpSWgGZHlg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":462690},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-core-0.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/98c06a946286ed4d8fab1af958477629/aegis-sdk-core-0.1.0.tgz","_integrity":"sha512-jd7cZbjxEr6NmN/9medqa3bqm1mFbi6v4U7fb4lQy68yXtYF1kKy0tstPqkLoAIjRBOw1r5ELjX1rZmKhEdOww==","repository":{"url":"git+https://github.com/aegis-sdk/aegis.git","type":"git","directory":"packages/core"},"_npmVersion":"10.9.4","description":"Streaming-first prompt injection defense for AI applications","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.1.0_1771370516012_0.3346661485003555","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aegis-sdk/core","version":"0.2.0","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"license":"MIT","_id":"@aegis-sdk/core@0.2.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"homepage":"https://github.com/aegis-sdk/aegis#readme","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"dist":{"shasum":"d636af0f200fec11093cf050926883b34dd67263","tarball":"https://registry.npmjs.org/@aegis-sdk/core/-/core-0.2.0.tgz","fileCount":8,"integrity":"sha512-cSBuMgZ+j4C5Guk11tEa1bkHhdbky2OEMablTAo5Shjs/2Og7NzIwdF/KY5jLYXxftohayLtI3Y1TyfjJP1CRQ==","signatures":[{"sig":"MEQCIAH4eqblAv9W3mFXZ8kf7lqw720cBdMcIuyTridcTA5AAiAWTnk122MxOGVM4gHwaaWNk7m3rUTWAVSSHGPw4gBYWw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":638258},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-core-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/ed9520a45e5ed7fe74bba89a97812474/aegis-sdk-core-0.2.0.tgz","_integrity":"sha512-cSBuMgZ+j4C5Guk11tEa1bkHhdbky2OEMablTAo5Shjs/2Og7NzIwdF/KY5jLYXxftohayLtI3Y1TyfjJP1CRQ==","repository":{"url":"git+https://github.com/aegis-sdk/aegis.git","type":"git","directory":"packages/core"},"_npmVersion":"10.9.4","description":"Streaming-first prompt injection defense for AI applications","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.2.0_1771372100102_0.7308497935902787","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aegis-sdk/core","version":"0.3.0","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"license":"MIT","_id":"@aegis-sdk/core@0.3.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"homepage":"https://github.com/aegis-sdk/aegis#readme","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"dist":{"shasum":"a1e6df687cf8690795b4fcb47e072c2c1437e0b9","tarball":"https://registry.npmjs.org/@aegis-sdk/core/-/core-0.3.0.tgz","fileCount":8,"integrity":"sha512-xP7yUxURNAzJ5IfWHwNb2nk0wBaRFKkWzEe/IeqWhd+lv+JPgOhgQ3Zp4Q97Gl4NBa6EKcq9OECr088/bQkVWA==","signatures":[{"sig":"MEUCIQDmbOmm0FBpmmEuMNvrQLuoQGP5W+fPI+1lT0iYDAcGFwIgUFp4BkSlAIKLgXkx1PHZB0GezKk0WboiLBET8vhcAXk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":893296},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-core-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/4fe9ead7e07c6d756c4749bdeab13300/aegis-sdk-core-0.3.0.tgz","_integrity":"sha512-xP7yUxURNAzJ5IfWHwNb2nk0wBaRFKkWzEe/IeqWhd+lv+JPgOhgQ3Zp4Q97Gl4NBa6EKcq9OECr088/bQkVWA==","repository":{"url":"git+https://github.com/aegis-sdk/aegis.git","type":"git","directory":"packages/core"},"_npmVersion":"10.9.4","description":"Streaming-first prompt injection defense for AI applications","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.3.0_1771394272858_0.3551752607151495","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aegis-sdk/core","version":"0.5.0","description":"Streaming-first prompt injection defense for AI applications","license":"MIT","type":"module","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"repository":{"type":"git","url":"git+https://github.com/aegis-sdk/aegis.git","directory":"packages/core"},"engines":{"node":">=18.0.0"},"sideEffects":false,"devDependencies":{"@types/node":"^25.2.3"},"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"_id":"@aegis-sdk/core@0.5.0","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"homepage":"https://github.com/aegis-sdk/aegis#readme","_integrity":"sha512-V8hvkEZEzI6tfbJP2WzB5P8ooxYlbZYjU0oNyy2cfoXFpBUeaZCL55Bm8iTyTI0SVQSsZeQ1ZR+UPx2vza+PtA==","_resolved":"/tmp/fe23af5277f1bf7e8ea69588fad3630f/aegis-sdk-core-0.5.0.tgz","_from":"file:aegis-sdk-core-0.5.0.tgz","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-V8hvkEZEzI6tfbJP2WzB5P8ooxYlbZYjU0oNyy2cfoXFpBUeaZCL55Bm8iTyTI0SVQSsZeQ1ZR+UPx2vza+PtA==","shasum":"1a2a9f299fcf3257cb41ba4cc02bdf2d2e679bdc","tarball":"https://registry.npmjs.org/@aegis-sdk/core/-/core-0.5.0.tgz","fileCount":9,"unpackedSize":1263376,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHCkDfXndN1mzCOaOzCyo6al+BxrwsAQG7CBFeoG6sfwAiAi6TJjqWlkw82lozBzblyvbRoBHBwf4B/FJh+m4aoDug=="}]},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"directories":{},"maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/core_0.5.0_1771972389730_0.671760372640194"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-17T22:37:59.957Z","modified":"2026-02-24T22:33:10.157Z","0.0.0":"2026-02-17T22:38:00.237Z","0.1.0":"2026-02-17T23:21:56.195Z","0.2.0":"2026-02-17T23:48:20.296Z","0.3.0":"2026-02-18T05:57:52.998Z","0.5.0":"2026-02-24T22:33:10.028Z"},"bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"license":"MIT","homepage":"https://github.com/aegis-sdk/aegis#readme","keywords":["ai","llm","prompt-injection","security","streaming","defense","guard","openai","anthropic","vercel-ai"],"repository":{"type":"git","url":"git+https://github.com/aegis-sdk/aegis.git","directory":"packages/core"},"description":"Streaming-first prompt injection defense for AI applications","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"readme":"# @aegis-sdk/core\n\nStreaming-first prompt injection defense for JavaScript/TypeScript AI applications.\n\nPart of the [Aegis.js](https://github.com/aegis-sdk/Aegis) prompt injection defense toolkit.\n\n## Installation\n\n```bash\nnpm install @aegis-sdk/core\n```\n\n## Quick Start\n\n```typescript\nimport { Aegis } from '@aegis-sdk/core';\n\nconst aegis = new Aegis({ policy: 'strict' });\n\n// Scan input messages before sending to the LLM\nconst safeMessages = await aegis.guardInput(messages);\n\n// Monitor the output stream in real-time (kills on violation)\nconst transform = aegis.createStreamTransform();\n```\n\nWith the Vercel AI SDK:\n\n```typescript\nimport { streamText } from 'ai';\nimport { openai } from '@ai-sdk/openai';\nimport { Aegis } from '@aegis-sdk/core';\n\nconst aegis = new Aegis({ policy: 'strict' });\n\nexport async function POST(req: Request) {\n  const { messages } = await req.json();\n\n  const safeMessages = await aegis.guardInput(messages);\n\n  const result = streamText({\n    model: openai('gpt-4o'),\n    messages: safeMessages,\n    experimental_transform: aegis.createStreamTransform(),\n  });\n\n  return result.toDataStreamResponse();\n}\n```\n\n## API\n\n### `Aegis` class\n\nThe main entry point. Accepts an `AegisConfig` with a policy preset (`'strict'`, `'balanced'`, `'permissive'`) or a custom policy object.\n\n- **`guardInput(messages, options?)`** -- Scan messages for prompt injection. Returns messages if safe, throws `AegisInputBlocked` if blocked.\n- **`createStreamTransform()`** -- Returns a `TransformStream<string, string>` that monitors output tokens and kills the stream on violation.\n- **`guardChainStep(output, options)`** -- Guard a single step in an agentic loop. Tracks cumulative risk, enforces step budgets, and applies privilege decay.\n- **`scanMedia(content, mediaType)`** -- Scan images, audio, or documents for injection attempts (requires `multiModal` config).\n- **`judgeOutput(userRequest, modelOutput, context?)`** -- Evaluate model output against original user intent using an LLM-Judge (requires `judge` config).\n- **`getAuditLog()`** -- Access the audit log for querying security events.\n- **`getValidator()`** -- Access the action validator for tool call validation.\n- **`getPolicy()`** -- Access the resolved policy.\n- **`getMessageSigner()`** -- Access the HMAC message signer (returns `null` if integrity is not configured).\n- **`isSessionQuarantined()`** -- Check whether the current session has been quarantined.\n\n### `aegis` singleton\n\nConvenience singleton for the \"simple path\" API:\n\n```typescript\nimport { aegis } from '@aegis-sdk/core';\n\naegis.configure({ policy: 'strict' });\nconst instance = aegis.getInstance();\n```\n\n### Core modules\n\nEach module is exported individually for standalone use:\n\n| Export | Purpose |\n|--------|---------|\n| `quarantine(content, options?)` | Wrap content as `Quarantined<T>` to track trust |\n| `isQuarantined(value)` | Check if a value is quarantined |\n| `InputScanner` | Pattern matching + heuristic injection detection |\n| `PerplexityAnalyzer` | Character n-gram perplexity for adversarial suffix detection |\n| `TrajectoryAnalyzer` | Multi-turn escalation detection (Crescendo attacks) |\n| `PromptBuilder` | Sandwich-pattern prompt construction with delimiters |\n| `StreamMonitor` | Real-time output scanning via `TransformStream` |\n| `ActionValidator` | Tool call validation + rate limiting |\n| `Sandbox` | Zero-capability model for untrusted content |\n| `LLMJudge` | Provider-agnostic intent alignment verification |\n| `MultiModalScanner` | Extract + scan text from images/audio/documents |\n| `AutoRetryHandler` | Retry with escalated security after a block |\n| `AuditLog` | Security event logging |\n| `FileTransport` | JSONL file transport with rotation |\n| `OTelTransport` | OpenTelemetry spans/metrics/logs transport |\n| `AlertingEngine` | Real-time alerting (rate-spike, session-kills) |\n| `MessageSigner` | HMAC conversation integrity |\n\n### Policy helpers\n\n```typescript\nimport { resolvePolicy, getPreset, isActionAllowed, loadPolicyFile } from '@aegis-sdk/core';\n\nconst policy = resolvePolicy('strict');\nconst preset = getPreset('balanced');\nconst allowed = isActionAllowed(policy, 'search_kb');\nconst filePolicy = await loadPolicyFile('./aegis-policy.yaml');\n```\n\n### Error classes\n\n- **`AegisInputBlocked`** -- Thrown when input is blocked. Contains `scanResult` with detections and score.\n- **`AegisSessionQuarantined`** -- Thrown when a quarantined session attempts input.\n- **`AegisSessionTerminated`** -- Thrown on critical violations. Session must be recreated.\n\n## Canary Tokens\n\nEmbed canary tokens in your system prompt to detect when the model leaks it:\n\n```typescript\nconst aegis = new Aegis({\n  policy: 'strict',\n  canaryTokens: ['AEGIS_CANARY_7f3a9b'],\n});\n```\n\nIf the model outputs a canary token, the stream monitor kills the stream immediately.\n\n## Preset Policies\n\n```typescript\nnew Aegis({ policy: 'strict' });      // High security, tighter thresholds\nnew Aegis({ policy: 'balanced' });    // Default -- good for most apps\nnew Aegis({ policy: 'permissive' });  // Lower friction, wider thresholds\n```\n\n## Learn More\n\n- [Documentation](https://aegis-sdk.github.io/Aegis/)\n- [GitHub](https://github.com/aegis-sdk/Aegis)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}