{"_id":"@andrewlabs/openclaw-messageguard-ml","_rev":"5-8414a19bbc6e1ca7cff42a4d74bced6e","name":"@andrewlabs/openclaw-messageguard-ml","dist-tags":{"latest":"1.2.1"},"versions":{"1.0.0":{"name":"@andrewlabs/openclaw-messageguard-ml","version":"1.0.0","keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"author":{"name":"AndrewAndersen"},"license":"MIT","_id":"@andrewlabs/openclaw-messageguard-ml@1.0.0","maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"homepage":"https://github.com/AndrewAndrewsen/MessageGuard#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard/issues"},"dist":{"shasum":"f583d75bbe737fff26ad90a4ead833823f1ff4fe","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard-ml/-/openclaw-messageguard-ml-1.0.0.tgz","fileCount":10,"integrity":"sha512-TT/Ap3wxm9NqbRLT2LEGrWbILxXuNgmedroJA4J6oBFt3xwfB8NdAB4HEiA3Y0DiOeSQYT0GXDTIn7SkkaXiGA==","signatures":[{"sig":"MEUCIQDDVktzD7/uPmKshLowEszHHb+abKP545Ex7nad2p3fKgIgWSNfeOsvDCVYtpxenWoedqTKPDueXa/D0Tc+UPsYymM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14630},"main":"./index.js","type":"module","types":"./index.d.ts","gitHead":"67ac3602c1252c5029b2148e61b78008df6771e8","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"openclaw":{"extensions":["./index.js"]},"repository":{"url":"git+https://github.com/AndrewAndrewsen/MessageGuard.git","type":"git"},"_npmVersion":"11.8.0","description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"@huggingface/transformers":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.5","@types/node":"^22.0.0"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openclaw-messageguard-ml_1.0.0_1771959800218_0.5600562227745127","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@andrewlabs/openclaw-messageguard-ml","version":"1.0.1","keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"author":{"name":"AndrewAndersen"},"license":"MIT","_id":"@andrewlabs/openclaw-messageguard-ml@1.0.1","maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"homepage":"https://github.com/AndrewAndrewsen/MessageGuard-ML#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard-ML/issues"},"dist":{"shasum":"bced09e4a6e1d312b757a810f471f79e2182b95d","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard-ml/-/openclaw-messageguard-ml-1.0.1.tgz","fileCount":10,"integrity":"sha512-y64kGI0kd6/3+CwJHcAvZrYIpCO0evyKDoU1dt11o6LNvlDoEzquIAK4giFfyilM9lN8uH270nv92C1w9Kj+Yw==","signatures":[{"sig":"MEUCIDkxzUSYOS5v4UM2FaIaaDPB+EPhkkF506SGYFGN/2XoAiEA23U4pWUkUY0WAa87shm9aIq86DYSxuBX8qA0H0j4dAk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14639},"main":"./index.js","type":"module","types":"./index.d.ts","gitHead":"f2af33abd123ce3bc6a6f8ab1575ab006f066056","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"openclaw":{"extensions":["./index.js"]},"repository":{"url":"git+https://github.com/AndrewAndrewsen/MessageGuard-ML.git","type":"git"},"_npmVersion":"11.8.0","description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"@huggingface/transformers":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.5","@types/node":"^22.0.0"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openclaw-messageguard-ml_1.0.1_1771966086281_0.5562716727598287","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@andrewlabs/openclaw-messageguard-ml","version":"1.1.0","keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"author":{"name":"AndrewAndersen"},"license":"MIT","_id":"@andrewlabs/openclaw-messageguard-ml@1.1.0","maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"homepage":"https://github.com/AndrewAndrewsen/MessageGuard-ML#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard-ML/issues"},"dist":{"shasum":"0fdea1a81662d20e212602840bb1767d23073818","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard-ml/-/openclaw-messageguard-ml-1.1.0.tgz","fileCount":10,"integrity":"sha512-npL/vZNHDq8xnBBQezEslzQJ/df6COstYidW3Da6oA2gcmImLPzyZVONz4NN+0NF03WHYZR+w903EkaejeYkSQ==","signatures":[{"sig":"MEUCIQD5YgEq40oYr/qcOwJoyRAA21pdZkbsAJB/Y4fJ4MEDWAIgMBT8IxDlD+enSLeTWFtvh92NLVWDxvpyVzEibnHdn1k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15509},"main":"./index.js","type":"module","types":"./index.d.ts","gitHead":"60561015b4382ea156245a08d0d6cd1fbc2b3c39","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"openclaw":{"extensions":["./index.js"]},"repository":{"url":"git+https://github.com/AndrewAndrewsen/MessageGuard-ML.git","type":"git"},"_npmVersion":"11.8.0","description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"@huggingface/transformers":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.5","@types/node":"^22.0.0"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openclaw-messageguard-ml_1.1.0_1771966654873_0.21869250912686322","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@andrewlabs/openclaw-messageguard-ml","version":"1.2.0","keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"author":{"name":"AndrewAndersen"},"license":"MIT","_id":"@andrewlabs/openclaw-messageguard-ml@1.2.0","maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"homepage":"https://github.com/AndrewAndrewsen/MessageGuard-ML#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard-ML/issues"},"dist":{"shasum":"e96888a3622e8ff7a5f78e64469115a27b94c9e5","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard-ml/-/openclaw-messageguard-ml-1.2.0.tgz","fileCount":10,"integrity":"sha512-Fp75qQ895yHUwN6ylAPmqHVTONHYiQL8Qucc+MDqpSwKfG/GsFwYP02/MWUaflP+FyjUvN4T0GrCud4Ekk6sAQ==","signatures":[{"sig":"MEYCIQDBu5HUVOAV5r+G5zSjudH9hBPC0G4MZXWxhZM7FkYNOgIhAN3zZzGPv6m545BhGrEY3/rz1Ex44/Kek/zF6dtcxPgd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21602},"main":"./index.js","type":"module","types":"./index.d.ts","gitHead":"7040436957150166b1de6ece4565a7fa24bf6a31","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"openclaw":{"extensions":["./index.js"]},"repository":{"url":"git+https://github.com/AndrewAndrewsen/MessageGuard-ML.git","type":"git"},"_npmVersion":"11.8.0","description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"@huggingface/transformers":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.0.0"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openclaw-messageguard-ml_1.2.0_1772018012292_0.4939022096165495","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@andrewlabs/openclaw-messageguard-ml","version":"1.2.1","description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","type":"module","main":"./index.js","types":"./index.d.ts","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"author":{"name":"AndrewAndersen"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/AndrewAndrewsen/MessageGuard-ML.git"},"homepage":"https://github.com/AndrewAndrewsen/MessageGuard-ML#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard-ML/issues"},"openclaw":{"extensions":["./index.js"]},"dependencies":{"@huggingface/transformers":"^3.0.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.9.3"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"gitHead":"09e64bd0c5fa1621678bb299feb1ac700e0dc9fc","_id":"@andrewlabs/openclaw-messageguard-ml@1.2.1","_nodeVersion":"24.13.1","_npmVersion":"11.8.0","dist":{"integrity":"sha512-aBKmk9hPTvs+jybA0Lhv3BJQPGuFFfweRyTHF/oieS7CRlCFTGZ+mTq3FRscQk72umwoDjd0Ap3lKys9skAsyQ==","shasum":"38e05033b96d98c099c0272ace02f1646f47535a","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard-ml/-/openclaw-messageguard-ml-1.2.1.tgz","fileCount":10,"unpackedSize":21896,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDIspOkYU/SmnpgseqSAgyPouPU6UW+IimJIQKr66CDBwIgfgAKUbYL9WSdykS/jG268elAUd8MpK+tw6WX5Ytu038="}]},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"directories":{},"maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-messageguard-ml_1.2.1_1772018062276_0.999589879689758"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-24T19:03:20.139Z","modified":"2026-02-25T11:14:22.559Z","1.0.0":"2026-02-24T19:03:20.367Z","1.0.1":"2026-02-24T20:48:06.440Z","1.1.0":"2026-02-24T20:57:35.014Z","1.2.0":"2026-02-25T11:13:32.465Z","1.2.1":"2026-02-25T11:14:22.434Z"},"bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard-ML/issues"},"author":{"name":"AndrewAndersen"},"license":"MIT","homepage":"https://github.com/AndrewAndrewsen/MessageGuard-ML#readme","keywords":["openclaw","openclaw-plugin","messageguard","machine-learning","onnx","transformers"],"repository":{"type":"git","url":"git+https://github.com/AndrewAndrewsen/MessageGuard-ML.git"},"description":"OpenClaw plugin: ML-based secret detection and redaction for outgoing messages using transformers.js/ONNX.","maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"readme":"# @andrewlabs/openclaw-messageguard-ml\n\nML-powered companion plugin to `@andrewlabs/openclaw-messageguard`.\n\nThis plugin uses a DistilBERT token classification model via `@huggingface/transformers` (ONNX Runtime under the hood) to detect sensitive content in outgoing messages and replace detected spans with `[REDACTED]`.\n\n## Features\n\n- OpenClaw `before_tool_call` hook — intercepts `message` tool sends before execution\n- OpenClaw `message_sending` hook — intercepts agent replies (when wired up by the gateway)\n- Automatic model download from Hugging Face on first use (then cached locally)\n- Fails open: if model download/inference fails, message passes through unchanged\n- Configurable model id, confidence threshold, and redaction token\n\n## Install\n\n```bash\nopenclaw plugins install @andrewlabs/openclaw-messageguard-ml\nopenclaw gateway restart\n```\n\nOr via npm:\n\n```bash\nnpm install @andrewlabs/openclaw-messageguard-ml\n```\n\nEnsure your OpenClaw plugin loader can discover package extensions via `openclaw.extensions`.\n\n## Manifest\n\nThe package includes `openclaw.plugin.json` with plugin id `messageguard-ml` and configuration schema.\n\n## Configuration\n\n`openclaw.plugin.json` supports:\n\n- `enabled` (boolean, default `true`)\n- `modelId` (string, default `AndrewAndrewsen/distilbert-secret-masker`)\n- `threshold` (number, 0-1, default `0.5`)\n- `mask` (string, default `[REDACTED]`)\n\n## How it Works\n\n1. On plugin startup, two hooks are registered:\n   - `before_tool_call` — primary enforcement; intercepts `message` tool sends (action `send`/`broadcast`) and redacts sensitive content in the message parameter before the tool executes.\n   - `message_sending` — secondary; intercepts agent replies in the delivery pipeline. Note: in OpenClaw 2026.2.x, this hook does not fire for all outbound paths (see [openclaw#XXXX](https://github.com/openclaw/openclaw/issues)).\n2. For each outgoing message, the model runs token classification.\n3. Spans predicted as sensitive at/above threshold are grouped, reconstructed to character offsets, extended to word boundaries, and merged.\n4. Sanitized content is returned to OpenClaw.\n\nIf model loading or inference fails (for example, model repo not yet available), the plugin logs a warning and returns without modifying the message.\n\n## Changelog\n\n### 1.2.0\n\n- **Fix: Hook now fires.** Switched primary hook from `message_sending` (not fired for tool sends in 2026.2.x) to `before_tool_call`, which reliably intercepts `message` tool sends. `message_sending` is kept as a secondary hook for future compatibility.\n- **Fix: Span reconstruction.** The DistilBERT tokenizer produces subword tokens (`##ia`, `##9`, etc.) and `transformers.js` returns `undefined` for `start`/`end` offsets. The previous `indexOf`-per-subword approach matched fragments at wrong positions, causing partial/broken redaction. New approach: group consecutive sensitive subword tokens into word groups, reconstruct the full text fragment, find it case-insensitively in the original text, and extend to word boundaries to catch trailing characters the tokenizer dropped.\n\n### 1.1.0\n\n- Initial release with `message_sending` hook and basic span reconstruction.\n\n## Exporting/Quantizing ONNX\n\nUse the helper script:\n\n```bash\npython3 scripts/export_onnx.py\n```\n\nOptional push to Hugging Face (requires token):\n\n```bash\nHF_TOKEN=... python3 scripts/export_onnx.py --push\n```\n\nIf `AndrewAndrewsen/distilbert-secret-masker` does not exist on Hugging Face, the script exits with a clear warning.\n\n## Comparison With Regex Plugin\n\n- `@andrewlabs/openclaw-messageguard`: deterministic regex rules and policy actions\n- `@andrewlabs/openclaw-messageguard-ml`: learned token classification for broader, context-sensitive detection\n\nRunning both can provide layered defense.\n\n## Development\n\n```bash\nnpm install\nnpm run build\n```\n","readmeFilename":"README.md"}