{"_id":"@aegis-sdk/ollama","_rev":"2-1a2b7ab0890bfb4c020c7a74d27b8f04","name":"@aegis-sdk/ollama","dist-tags":{"latest":"0.5.0"},"versions":{"0.3.0":{"name":"@aegis-sdk/ollama","version":"0.3.0","license":"MIT","_id":"@aegis-sdk/ollama@0.3.0","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"dist":{"shasum":"0263a9ba5a1a27a074ce4e9d68ec11a37f39ebd4","tarball":"https://registry.npmjs.org/@aegis-sdk/ollama/-/ollama-0.3.0.tgz","fileCount":8,"integrity":"sha512-CD7dbieWfCKnuO0hLpNCbhAtKFu48jHYhkidOzVLzv2FlZgA3nhiG9+PSu8wOX2LNBlZZoGrd88PhRQckVrziA==","signatures":[{"sig":"MEMCH1Mg9i7gGMkhxaATLjg7lhxw4Ww7oiuSqps+/Q4ZoMwCIGpdLRV+Ie1cmxEZ+nKcmBtavTeiNBoX3zGTkzXrJ9IH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":55795},"main":"./dist/index.cjs","type":"module","_from":"file:aegis-sdk-ollama-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"dev":"tsup --watch","build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"_resolved":"/tmp/01c1312dc550ddccfaee0ce5308d0376/aegis-sdk-ollama-0.3.0.tgz","_integrity":"sha512-CD7dbieWfCKnuO0hLpNCbhAtKFu48jHYhkidOzVLzv2FlZgA3nhiG9+PSu8wOX2LNBlZZoGrd88PhRQckVrziA==","_npmVersion":"10.9.4","description":"Ollama SDK adapter for Aegis prompt injection defense","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"@aegis-sdk/core":"0.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"ollama":">=0.5.0","@aegis-sdk/core":"0.3.0"},"_npmOperationalInternal":{"tmp":"tmp/ollama_0.3.0_1771394277677_0.8890855788134335","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aegis-sdk/ollama","version":"0.5.0","description":"Ollama SDK adapter for Aegis prompt injection defense","license":"MIT","type":"module","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","peerDependencies":{"ollama":">=0.5.0","@aegis-sdk/core":"0.5.0"},"dependencies":{"@aegis-sdk/core":"0.5.0"},"engines":{"node":">=18.0.0"},"sideEffects":false,"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"_id":"@aegis-sdk/ollama@0.5.0","_integrity":"sha512-ZqW4iR2V/PeMIRVQUEkuwEx7sh/rt3wuKuww15MRHArk9bsP8NCKHqhhjnMo7O1pjIL5mRBn9AM9IlXkrprBQA==","_resolved":"/tmp/21c73736e9695bf0f2a50907d1bb17af/aegis-sdk-ollama-0.5.0.tgz","_from":"file:aegis-sdk-ollama-0.5.0.tgz","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-ZqW4iR2V/PeMIRVQUEkuwEx7sh/rt3wuKuww15MRHArk9bsP8NCKHqhhjnMo7O1pjIL5mRBn9AM9IlXkrprBQA==","shasum":"423b6ab67a78a09f1d680c55bbcdb5c29a10c417","tarball":"https://registry.npmjs.org/@aegis-sdk/ollama/-/ollama-0.5.0.tgz","fileCount":9,"unpackedSize":58335,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFHdJJqdsuaxvT06dgOG9f61nuDL8Op6AvHl2QXScwtZAiAf3b+RQBw2t4EPfLii04WwcHuib0YvyhhcRDFdtO+zKA=="}]},"_npmUser":{"name":"msjoshlopez","email":"josh@memberstack.com"},"directories":{},"maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ollama_0.5.0_1771972393309_0.6515542282738669"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-18T05:57:57.603Z","modified":"2026-02-24T22:33:13.574Z","0.3.0":"2026-02-18T05:57:57.818Z","0.5.0":"2026-02-24T22:33:13.452Z"},"license":"MIT","description":"Ollama SDK adapter for Aegis prompt injection defense","maintainers":[{"name":"msjoshlopez","email":"josh@memberstack.com"}],"readme":"# @aegis-sdk/ollama\n\nOllama adapter for Aegis prompt injection defense. Scans messages and monitors streaming responses for local model usage via Ollama.\n\nPart of the [Aegis.js](https://github.com/aegis-sdk/Aegis) prompt injection defense toolkit.\n\n## Installation\n\n```bash\nnpm install @aegis-sdk/ollama @aegis-sdk/core ollama\n```\n\n## Quick Start\n\nWrap the Ollama client for automatic protection:\n\n```typescript\nimport { Ollama } from 'ollama';\nimport { Aegis } from '@aegis-sdk/core';\nimport { wrapOllamaClient } from '@aegis-sdk/ollama';\n\nconst aegis = new Aegis({ policy: 'strict' });\nconst client = wrapOllamaClient(new Ollama(), aegis);\n\n// Messages are scanned before sending.\n// Streaming responses are monitored in real-time.\nconst response = await client.chat({\n  model: 'llama3',\n  messages: [{ role: 'user', content: 'Hello!' }],\n});\n```\n\nOr scan messages manually:\n\n```typescript\nimport { Aegis } from '@aegis-sdk/core';\nimport { guardMessages } from '@aegis-sdk/ollama';\n\nconst aegis = new Aegis({ policy: 'strict' });\n\nconst messages = [\n  { role: 'system' as const, content: 'You are a helpful assistant.' },\n  { role: 'user' as const, content: userInput },\n];\n\n// Throws AegisInputBlocked if injection is detected\nconst safe = await guardMessages(aegis, messages);\n```\n\n## API\n\n### `wrapOllamaClient(client, aegis, options?)`\n\nProxy the Ollama client to automatically guard `chat()` calls. Input messages are scanned before sending, and streaming responses (when `stream: true`) are monitored in real-time. All other client methods pass through unchanged.\n\n### `guardMessages(aegis, messages, options?)`\n\nScan an array of `OllamaMessage[]` for prompt injection. Ollama uses the standard system/user/assistant roles, which map directly to the Aegis three-role model. Returns the original messages if safe, throws `AegisInputBlocked` if blocked.\n\n### `createStreamTransform(aegis)`\n\nCreate a `TransformStream<string, string>` for monitoring extracted `message.content` values from Ollama streaming chunks.\n\n### `getAuditLog(aegis)`\n\nConvenience accessor for the Aegis audit log.\n\n## Why protect local models?\n\nLocal models running through Ollama still process untrusted user input. Prompt injection attacks work regardless of where the model runs. If your application takes user input and passes it to a local LLM that has access to tools, files, or databases, the same attack vectors apply.\n\n## Learn More\n\n- [Documentation](https://aegis-sdk.github.io/Aegis/)\n- [GitHub](https://github.com/aegis-sdk/Aegis)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}