{"_id":"@aegis-sdk/koa","_rev":"2-e9171681bd598a9262230e1c261ee2db","name":"@aegis-sdk/koa","dist-tags":{"latest":"0.5.0"},"versions":{"0.3.0":{"name":"@aegis-sdk/koa","version":"0.3.0","license":"MIT","_id":"@aegis-sdk/koa@0.3.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"homepage":"https://github.com/aegis-sdk/aegis#readme","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"dist":{"shasum":"60042317058220cfb3ab25c86348c14dd65a7360","tarball":"https://registry.npmjs.org/@aegis-sdk/koa/-/koa-0.3.0.tgz","fileCount":8,"integrity":"sha512-lbOFt6NzV+pMaRiXrNbdoOJf7T/tqMeezfi7MD/57xpKq8Yh+43mLhQOMkExwrFRwrwJVa7MYrbGVlAuQyAj8Q==","signatures":[{"sig":"MEQCIGYhKOvWObZeKpXQxxalJyseqFTVAu/MZqlO4qICQDjDAiAMfV87z1c2S1DEcbTjej2OCnRM0oW7JNt38z2KnwYrvA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":56455},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-koa-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/b1796b786ac9cef365ed0fc1aa8a61db/aegis-sdk-koa-0.3.0.tgz","_integrity":"sha512-lbOFt6NzV+pMaRiXrNbdoOJf7T/tqMeezfi7MD/57xpKq8Yh+43mLhQOMkExwrFRwrwJVa7MYrbGVlAuQyAj8Q==","repository":{"url":"git+https://github.com/aegis-sdk/aegis.git","type":"git","directory":"packages/koa"},"_npmVersion":"10.9.4","description":"Koa middleware adapter for Aegis prompt injection defense","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"@aegis-sdk/core":"0.3.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/koa":"^2.15.0","@types/koa-bodyparser":"^4.3.12"},"peerDependencies":{"koa":">=2.0.0","@aegis-sdk/core":"0.3.0"},"_npmOperationalInternal":{"tmp":"tmp/koa_0.3.0_1771964663398_0.6151947308694683","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aegis-sdk/koa","version":"0.5.0","description":"Koa middleware adapter for Aegis prompt injection defense","license":"MIT","type":"module","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","peerDependencies":{"koa":">=2.0.0","@aegis-sdk/core":"0.5.0"},"dependencies":{"@aegis-sdk/core":"0.5.0"},"devDependencies":{"@types/koa":"^2.15.0","@types/koa-bodyparser":"^4.3.12"},"repository":{"type":"git","url":"git+https://github.com/aegis-sdk/aegis.git","directory":"packages/koa"},"engines":{"node":">=18.0.0"},"sideEffects":false,"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"_id":"@aegis-sdk/koa@0.5.0","bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"homepage":"https://github.com/aegis-sdk/aegis#readme","_integrity":"sha512-hcUd4VlO/2tnS3RSEhBBdosH87UKhhq8gSKNKgUgOk/vf/2GB8OK1hKl4CVHx0gGWhNmaY9Ag73YyLpQpwdfxQ==","_resolved":"/tmp/bab649e2b19c4aa0339e67216075b424/aegis-sdk-koa-0.5.0.tgz","_from":"file:aegis-sdk-koa-0.5.0.tgz","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-hcUd4VlO/2tnS3RSEhBBdosH87UKhhq8gSKNKgUgOk/vf/2GB8OK1hKl4CVHx0gGWhNmaY9Ag73YyLpQpwdfxQ==","shasum":"2c5abb65cc2740d62ddf32deb7c23fb6893a2048","tarball":"https://registry.npmjs.org/@aegis-sdk/koa/-/koa-0.5.0.tgz","fileCount":9,"unpackedSize":58969,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIB4nBiRhhj7y5pzZIHwTxz/raBNEMJLCL2qOuZ/N/dttAiBwnhRADxCfa0RgSx1DH1yGpVNTeiqCU/efGLAtm6v5dg=="}]},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"directories":{},"maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/koa_0.5.0_1771972390256_0.6234926230751341"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-24T20:24:23.297Z","modified":"2026-02-24T22:33:10.557Z","0.3.0":"2026-02-24T20:24:23.553Z","0.5.0":"2026-02-24T22:33:10.416Z"},"bugs":{"url":"https://github.com/aegis-sdk/aegis/issues"},"license":"MIT","homepage":"https://github.com/aegis-sdk/aegis#readme","repository":{"type":"git","url":"git+https://github.com/aegis-sdk/aegis.git","directory":"packages/koa"},"description":"Koa middleware adapter for Aegis prompt injection defense","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"readme":"# @aegis-sdk/koa\n\nKoa middleware for scanning LLM chat messages against prompt injection attacks.\n\nPart of the [Aegis.js](https://github.com/aegis-sdk/Aegis) prompt injection defense toolkit.\n\n## Installation\n\n```bash\nnpm install @aegis-sdk/koa @aegis-sdk/core\n```\n\n## Quick Start\n\n```ts\nimport Koa from 'koa';\nimport bodyParser from 'koa-bodyparser';\nimport { aegisMiddleware } from '@aegis-sdk/koa';\n\nconst app = new Koa();\napp.use(bodyParser());\napp.use(aegisMiddleware({ policy: 'strict' }));\n\napp.use(async (ctx) => {\n  const { messages, instance } = ctx.state.aegis; // scanned messages\n  // pass messages to your LLM\n  ctx.body = { reply: '...' };\n});\n\napp.listen(3000);\n```\n\n## API\n\n### `aegisMiddleware(options?)`\n\nCreates Koa middleware that reads `ctx.request.body.messages`, runs them through `aegis.guardInput()`, and attaches the safe messages to `ctx.state.aegis`. Returns 403 with violation details if input is blocked.\n\nRequires a body parsing middleware (e.g., `koa-bodyparser`) to be applied first.\n\nAccepts either an `AegisConfig` directly or an `AegisMiddlewareOptions` object:\n\n| Option | Type | Default | Description |\n|---|---|---|---|\n| `aegis` | `AegisConfig \\| Aegis` | `{}` | Aegis configuration or pre-constructed instance |\n| `messagesProperty` | `string` | `\"messages\"` | Property on `ctx.request.body` to read messages from |\n| `scanStrategy` | `ScanStrategy` | `\"last-user\"` | Which messages to scan |\n| `onBlocked` | `(ctx, detections, error) => boolean` | -- | Custom error handler. Return `true` to take over the response |\n\nAccess scan results in downstream middleware via `ctx.state.aegis`, which returns `{ messages, instance, auditLog }`.\n\n### `aegisStreamTransform(configOrInstance?)`\n\nReturns a `TransformStream<string, string>` that monitors LLM output tokens for injection payloads, PII leaks, and canary token leaks.\n\n```ts\napp.use(async (ctx) => {\n  const transform = aegisStreamTransform(ctx.state.aegis.instance);\n  const monitoredStream = llmStream.pipeThrough(transform);\n  // pipe the monitored stream to the response\n});\n```\n\n### `guardMessages(aegis, messages, options?)`\n\nScans messages directly without using the middleware. Throws `AegisInputBlocked` if input is blocked.\n\n### Re-exports\n\n`Aegis`, `AegisInputBlocked`, `AegisSessionQuarantined`, `AegisSessionTerminated`, and all core types are re-exported for convenience.\n\n## Learn More\n\n- [Documentation](https://aegis-sdk.github.io/Aegis/)\n- [GitHub](https://github.com/aegis-sdk/Aegis)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}