{"_id":"@auxdynamics/mastguard-agent-sdk","_rev":"4-9eb545a8ec4cad62eda452ce03de070b","name":"@auxdynamics/mastguard-agent-sdk","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@auxdynamics/mastguard-agent-sdk","version":"0.1.0","keywords":["ai-security","llm","agent","prompt-injection","guardrails","mastguard","agentshield","openai","anthropic","ai-governance"],"author":{"name":"AuxDynamics Inc.","email":"info@auxdynamics.com"},"license":"MIT","_id":"@auxdynamics/mastguard-agent-sdk@0.1.0","maintainers":[{"name":"auxdynamics","email":"info@auxdynamics.com"}],"homepage":"https://mastguard.io","bugs":{"url":"https://github.com/RahulSapparapu/mastguard/issues"},"dist":{"shasum":"a60b8d9f06d489e5d527dd7fd23bc9f21cf47aef","tarball":"https://registry.npmjs.org/@auxdynamics/mastguard-agent-sdk/-/mastguard-agent-sdk-0.1.0.tgz","fileCount":7,"integrity":"sha512-CQrp/h1cDD0O0fdant6/ogEfVrBcmqaho2aPCuZQuTSAlfaxHhLjt5SMEb0Ndju8qvFIWDwuLDU3SkJk6H56yg==","signatures":[{"sig":"MEQCIDb5a0Tvvs8mf2DHxURCuAuaE8YW+HLWg38XN4tiN7csAiBtxzyVH6pTbpmaYwIpJKv6E/6rpKS8vGKE+uwVW+0Ybg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68597},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"0cb2c2acdc36524a4dee90b1f2e05be05aa858f5","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","test:watch":"vitest","prepublishOnly":"npm run build","test:adversarial":"vitest run src/tests/adversarial"},"_npmUser":{"name":"auxdynamics","email":"info@auxdynamics.com"},"repository":{"url":"git+https://github.com/RahulSapparapu/mastguard.git","type":"git"},"_npmVersion":"10.8.2","description":"Runtime AI agent security SDK for MastGuard — prompt injection detection, scope enforcement, tamper-evident audit logging, and policy-based guardrails.","directories":{},"_nodeVersion":"20.20.2","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.0.0","typescript":"^5.8.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mastguard-agent-sdk_0.1.0_1779646715250_0.6999985419023589","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@auxdynamics/mastguard-agent-sdk","version":"0.1.1","keywords":["ai-security","llm","agent","prompt-injection","guardrails","mastguard","agentshield","openai","anthropic","ai-governance"],"author":{"name":"AuxDynamics Inc.","email":"info@auxdynamics.com"},"license":"MIT","_id":"@auxdynamics/mastguard-agent-sdk@0.1.1","maintainers":[{"name":"auxdynamics","email":"info@auxdynamics.com"}],"homepage":"https://mastguard.io","bugs":{"url":"https://github.com/RahulSapparapu/mastguard/issues"},"dist":{"shasum":"673929aea866958d48e1d57f1ec61807c7ffcf0e","tarball":"https://registry.npmjs.org/@auxdynamics/mastguard-agent-sdk/-/mastguard-agent-sdk-0.1.1.tgz","fileCount":7,"integrity":"sha512-p1b3/3+GVXG+ctLTZ+UzU5gOUNjvfN9VPQ0MSFAorzvFkRxao1IKzZUGJCKZiKk3/ePQ8m/S8MVSvye0e1N6Qw==","signatures":[{"sig":"MEUCID+lLJMeKShiGiJPlZeGlrSd7JK1/Xy1QZtzDJ82wJ6rAiEAzkpKXkPp0N/vff6N9O7DW6R1cj664GAcWpCi2epuDjg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":91948},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"8851bdc1ccf0a21bc40e183972fb7020411ea3b4","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","test:watch":"vitest","prepublishOnly":"npm run build","test:adversarial":"vitest run src/tests/adversarial"},"_npmUser":{"name":"auxdynamics","email":"info@auxdynamics.com"},"repository":{"url":"git+https://github.com/RahulSapparapu/mastguard.git","type":"git"},"_npmVersion":"10.8.2","description":"Runtime AI agent security SDK for MastGuard — prompt injection detection, scope enforcement, tamper-evident audit logging, and policy-based guardrails.","directories":{},"_nodeVersion":"20.20.2","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.0.0","typescript":"^5.8.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mastguard-agent-sdk_0.1.1_1780423070725_0.4603244436373579","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@auxdynamics/mastguard-agent-sdk","version":"0.2.1","keywords":["ai-security","llm","agent","prompt-injection","guardrails","mastguard","agentshield","openai","anthropic","ai-governance"],"author":{"name":"AuxDynamics Inc.","email":"info@auxdynamics.com"},"license":"MIT","_id":"@auxdynamics/mastguard-agent-sdk@0.2.1","maintainers":[{"name":"auxdynamics","email":"info@auxdynamics.com"}],"homepage":"https://mastguard.io","bugs":{"url":"https://github.com/RahulSapparapu/mastguard/issues"},"dist":{"shasum":"c42a93fc3e9d01dd4f94fc9d4ebaec723c84a812","tarball":"https://registry.npmjs.org/@auxdynamics/mastguard-agent-sdk/-/mastguard-agent-sdk-0.2.1.tgz","fileCount":7,"integrity":"sha512-8Iz7uWcrqOkbTrrx0+hjGcS8MW80J2PNijEj3iZ12qI/Jv9JEH6j0KpvXSztzXDXLWOfuNm8MPIawx3n5WhhjA==","signatures":[{"sig":"MEYCIQDZBV9Nj2dU7ewrJGpvfosmvYjobjSRhebAcPqPyy2l4wIhAOhIl228lM33oJfhr4MnsNAx5nasq1kkauxyemrncEZZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":130882},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"305948962b72b5e246cd8e524fdd00478f736e54","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","test:watch":"vitest","prepublishOnly":"npm run build","test:adversarial":"vitest run src/tests/adversarial"},"_npmUser":{"name":"auxdynamics","email":"info@auxdynamics.com"},"repository":{"url":"git+https://github.com/RahulSapparapu/mastguard.git","type":"git"},"_npmVersion":"10.8.2","description":"Runtime AI agent security SDK for MastGuard — prompt injection detection, scope enforcement, tamper-evident audit logging, and policy-based guardrails.","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^4.1.8","typescript":"^5.8.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mastguard-agent-sdk_0.2.1_1781139334063_0.5785496314679068","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@auxdynamics/mastguard-agent-sdk","version":"0.3.0","description":"Runtime AI agent security SDK for MastGuard — prompt injection detection, scope enforcement, tamper-evident audit logging, and policy-based guardrails.","license":"MIT","author":{"name":"AuxDynamics Inc.","email":"info@auxdynamics.com"},"homepage":"https://mastguard.io","repository":{"type":"git","url":"git+https://github.com/RahulSapparapu/mastguard.git"},"bugs":{"url":"https://github.com/RahulSapparapu/mastguard/issues"},"keywords":["ai-security","llm","agent","prompt-injection","guardrails","mastguard","agentshield","openai","anthropic","ai-governance"],"engines":{"node":">=18.0.0"},"main":"./dist/index.js","module":"./dist/index.mjs","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"publishConfig":{"access":"public"},"scripts":{"build":"tsup src/index.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build","test":"vitest run","test:watch":"vitest","test:adversarial":"vitest run src/tests/adversarial","lint":"tsc --noEmit"},"devDependencies":{"@types/node":"^22.0.0","tsup":"^8.0.0","typescript":"^5.8.0","vitest":"^4.1.8"},"_id":"@auxdynamics/mastguard-agent-sdk@0.3.0","gitHead":"841b56a8623837995f0b7fbd3e024bff1b501757","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-kIowmmG7VjVBqPu0vA7dHSRxihawmJxlUrVQyOLyoTHBmsaggdtPcvZiRkwBgyR7qlMTpIBUuEKlzNs/VklLvg==","shasum":"e0d5a136b4b480fab6e2583316beb7263eac11cd","tarball":"https://registry.npmjs.org/@auxdynamics/mastguard-agent-sdk/-/mastguard-agent-sdk-0.3.0.tgz","fileCount":7,"unpackedSize":153288,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIC7L52BeaF4Cu0LprxSI4AYFEvrYc291fAHQKLs0LGvcAiAYXcWSSVMXkato4vHJYrluXTsQNEIq+26LqCg1Pf0/TQ=="}]},"_npmUser":{"name":"auxdynamics","email":"info@auxdynamics.com"},"directories":{},"maintainers":[{"name":"auxdynamics","email":"info@auxdynamics.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mastguard-agent-sdk_0.3.0_1781202902913_0.49601971826269997"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-24T18:18:35.146Z","modified":"2026-06-11T18:35:03.306Z","0.1.0":"2026-05-24T18:18:35.423Z","0.1.1":"2026-06-02T17:57:50.884Z","0.2.1":"2026-06-11T00:55:34.202Z","0.3.0":"2026-06-11T18:35:03.108Z"},"bugs":{"url":"https://github.com/RahulSapparapu/mastguard/issues"},"author":{"name":"AuxDynamics Inc.","email":"info@auxdynamics.com"},"license":"MIT","homepage":"https://mastguard.io","keywords":["ai-security","llm","agent","prompt-injection","guardrails","mastguard","agentshield","openai","anthropic","ai-governance"],"repository":{"type":"git","url":"git+https://github.com/RahulSapparapu/mastguard.git"},"description":"Runtime AI agent security SDK for MastGuard — prompt injection detection, scope enforcement, tamper-evident audit logging, and policy-based guardrails.","maintainers":[{"name":"auxdynamics","email":"info@auxdynamics.com"}],"readme":"# @auxdynamics/mastguard-agent-sdk\n\n> Runtime AI security SDK for MastGuard — wraps any LLM call with prompt injection detection, scope enforcement, and tamper-evident audit logging.\n\n[![npm version](https://img.shields.io/npm/v/@auxdynamics/mastguard-agent-sdk)](https://www.npmjs.com/package/@auxdynamics/mastguard-agent-sdk)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n\n## Installation\n\n```bash\nnpm install @auxdynamics/mastguard-agent-sdk\n```\n\n## 5-Minute Quickstart\n\nThree lines to get monitoring (monitor mode never blocks — it just audits):\n\n```ts\nimport { wrapOpenAI, MastGuardShield } from '@auxdynamics/mastguard-agent-sdk';\nconst shield = new MastGuardShield({ apiKey: process.env.MASTGUARD_API_KEY!, organizationId: 'org-abc123', agentId: 'my-bot', mode: 'monitor' });\nconst openai = wrapOpenAI(new OpenAI(), shield); // use `openai` exactly as before\n```\n\nEvery `chat.completions.create()` call is now threat-scanned and written to\nMastGuard's tamper-evident audit trail. Flip `mode: 'block'` when you're\nready to enforce.\n\n## Full Quickstart\n\n```ts\nimport { MastGuardShield } from '@auxdynamics/mastguard-agent-sdk';\n\nconst shield = new MastGuardShield({\n  apiKey: process.env.MASTGUARD_API_KEY,\n  policy: 'standard',\n  agentId: 'my-customer-support-bot',\n  organizationId: 'org-abc123',\n});\n\nconst response = await shield.protect(\n  () => openai.chat.completions.create({ model: 'gpt-4o', messages }),\n  { sessionId: req.user.id, toolCalls: pendingToolCalls }\n);\n\nif (!response.allowed) {\n  console.log('Flagged:', response.violations);\n}\n```\n\n> Pass a **thunk** (`() => client.create(...)`) rather than a started Promise.\n> In `block` mode, input-level threats are evaluated *before* the LLM is\n> invoked — if the request is blocked, the LLM call never happens. A bare\n> Promise is still accepted for backward compatibility, but it has already\n> started the call by the time `protect()` sees it.\n\n## Pre-Call vs. Post-Call Blocking\n\n**Pre-call blocking for input-level threats (prompt injection, scope violation,\ntoken budget). Post-call blocking for output-level threats (data exfiltration,\nharm classification).**\n\n| Stage | Threats evaluated | LLM invoked on block? |\n| --- | --- | --- |\n| Pre-call (before dispatch) | Prompt injection (direct), scope violation (tool-call parameters), token budget threshold | **No** — the call is never made (thunk callers) |\n| Post-call (response required) | Data exfiltration, AgentHarm output classification, multi-step attack chain continuation | Yes — the response is withheld and `MastGuardBlockedError` is thrown |\n\n## Authentication\n\nGet your API key from **[https://app.mastguard.io/dashboard/developer](https://app.mastguard.io/dashboard/developer)** (Developer page → Create API key).\n\nPass it as `apiKey` in `ShieldConfig` or set the `MASTGUARD_API_KEY` environment variable. Every request the SDK makes — both event ingest and policy fetch — authenticates with the `X-API-Key` header.\n\n## Configuration\n\n| Option           | Type                   | Required | Default                      | Description                                               |\n| ---------------- | ---------------------- | -------- | ---------------------------- | --------------------------------------------------------- |\n| `apiKey`         | `string`               | Yes      | —                            | MastGuard API key from dashboard                          |\n| `policy`         | `string`               | Yes      | —                            | Policy name: `standard`, `hipaa`, or `enterprise`         |\n| `agentId`        | `string`               | Yes      | —                            | Unique identifier for this agent                          |\n| `organizationId` | `string`               | Yes      | —                            | Your MastGuard organization ID                            |\n| `endpoint`       | `string`               | No       | `https://api.mastguard.io`   | Override API base URL (staging / self-hosted)             |\n| `mode`           | `'block' \\| 'monitor'` | No       | `'block'`                    | `block` enforces policy; `monitor` logs only              |\n| `timeout`        | `number`               | No       | `3000`                       | Ingest API timeout in milliseconds                        |\n\n## Shield Methods\n\n### `shield.protect(llmCall, options)`\n\nWraps any LLM call — evaluates the request **before dispatch** (pre-call\nlayers) and the response after (post-call layers) against your configured\npolicy. In `block` mode, a violation at either stage throws\n`MastGuardBlockedError`; for pre-call violations the LLM is never invoked.\n\n```ts\nconst result = await shield.protect(\n  () => openai.chat.completions.create({ model: 'gpt-4o', messages }),\n  {\n    sessionId: 'session-xyz',   // required — ties events to a session\n    toolCalls: [...],           // optional — pending tool calls to inspect\n    userId: 'user-123',         // optional — for per-user audit trails\n    metadata: { env: 'prod' },  // optional — attached to audit records\n  }\n);\n```\n\n**Returns** `ShieldResult<T>`:\n\n| Field        | Type                 | Description                                      |\n| ------------ | -------------------- | ------------------------------------------------ |\n| `data`       | `T \\| null`          | The original LLM response (null if blocked)      |\n| `allowed`    | `boolean`            | `true` if the call passed all policy checks      |\n| `violations` | `ViolationRecord[]`  | List of policy violations found (empty if clean) |\n| `auditId`    | `string \\| undefined`| Tamper-evident audit record ID                   |\n| `sessionId`  | `string`             | Session ID echoed back for correlation           |\n\n## Detection Layers\n\n| Layer              | Rule ID           | What It Detects                                            | Research Basis   |\n| ------------------ | ----------------- | ---------------------------------------------------------- | ---------------- |\n| Prompt Injection   | `RULE-INJ-001`    | Direct instruction-override attempts in user input         | arXiv:2510.22620 |\n| Indirect Injection | `RULE-INJ-002`    | Instructions embedded in tool outputs or RAG results       | arXiv:2510.22620 |\n| Scope Violation    | `RULE-SCOPE-001`  | Tool calls outside the agent's declared policy             | arXiv:2510.22620 |\n| Data Exfiltration  | `RULE-EXFIL-PII-*`| PII, credentials, API keys in LLM responses                | arXiv:2510.22620 |\n| Multi-Step Attack  | `RULE-CHAIN-001`  | Sequential tool calls matching known attack chains         | arXiv:2603.11214 |\n\nAll detections are run by `ThreatDetector` and evaluated against your policy by `PolicyEngine`. Events are logged via `AuditLogger` with SHA-256 chain hashing for tamper evidence.\n\n## MCP Integration — `MastGuardMCPProxy`\n\nIndustry-first MCP-native security layer: every MCP tool call is\npolicy-checked **before** it reaches the MCP server, audited, and the\nresponse is scanned for data exfiltration before your agent sees it.\nExisting MCP clients need zero config changes.\n\n```ts\nimport { MastGuardMCPProxy, MastGuardBlockedError } from '@auxdynamics/mastguard-agent-sdk';\n\nconst proxy = new MastGuardMCPProxy('http://localhost:9000/rpc', {\n  apiKey: process.env.MASTGUARD_API_KEY!,\n  organizationId: 'org-abc123',\n  agentId: 'mcp-agent',\n  // Local rules; server-side \"mcp_tool_scope\" policy rules also apply.\n  toolScope: [\n    { tool_names: ['read_file', 'search_docs'], action: 'allow' }, // allowlist\n    // or: { tool_names: ['delete_database'], action: 'deny' }     // denylist\n  ],\n});\n\ntry {\n  const result = await proxy.proxyRequest('read_file', { path: '/docs/a.md' }, { sessionId: 'sess-1' });\n} catch (err) {\n  if (err instanceof MastGuardBlockedError) {\n    // Denied by mcp_tool_scope policy, or the response leaked credentials/PII.\n  }\n}\n```\n\nWhat happens on every `proxyRequest`:\n\n1. **Policy check before forwarding** — `mcp_tool_scope` rules (local +\n   server-side policy). Denied → `MastGuardBlockedError`, the MCP server is\n   never contacted.\n2. **Audit** — logged to MastGuard (`event_type: mcp_tool_call` /\n   `mcp_tool_blocked`).\n3. **Forward** — standard JSON-RPC 2.0 `tools/call` to the MCP server.\n4. **Response scan** — exfiltration + indirect-injection detection; critical\n   findings throw before the output reaches the caller.\n5. **Logged with latency + SHA-256 `output_hash`** — visible in the\n   AgentShield dashboard's **MCP Monitor** tab.\n\n## Integration Examples\n\n```ts\n// OpenAI\nimport OpenAI from 'openai';\nimport { wrapOpenAI } from '@auxdynamics/mastguard-agent-sdk';\nconst openai = wrapOpenAI(new OpenAI(), shield);\nconst res = await openai.chat.completions.create({ model: 'gpt-4o', messages });\n\n// Anthropic\nimport Anthropic from '@anthropic-ai/sdk';\nimport { wrapAnthropic } from '@auxdynamics/mastguard-agent-sdk';\nconst anthropic = wrapAnthropic(new Anthropic(), shield);\nconst msg = await anthropic.messages.create({ model: 'claude-sonnet-4-6', max_tokens: 1024, messages });\n\n// Azure OpenAI\nimport { AzureOpenAI } from 'openai';\nimport { wrapAzureOpenAI } from '@auxdynamics/mastguard-agent-sdk';\nconst azure = wrapAzureOpenAI(new AzureOpenAI({ endpoint, apiVersion }), shield);\n\n// MCP (see MCP Integration above)\nconst proxy = new MastGuardMCPProxy(mcpServerUrl, config);\n```\n\nStreaming is fully supported: `stream: true` returns a live `AsyncIterable`.\nIn `monitor` mode chunks pass through in real time and the assembled response\nis audited afterwards; in `block` mode the stream is buffered, scanned, and\nreplayed only if clean.\n\n## Troubleshooting — Top 5 Errors\n\n| Error | Cause | Fix |\n| --- | --- | --- |\n| `MastGuardBlockedError: ... prompt_injection` | The input tripped an injection rule in `block` mode | Inspect `err.violations[].evidence`; sanitize the input or run `monitor` mode to tune policy first |\n| `ingest non-200: 401 Unauthorized` | Invalid/revoked API key | Create a fresh key at app.mastguard.io → Developer; pass it as `apiKey` (`X-API-Key` header) |\n| `ingest non-200: 429` | Free plan 50K monthly event cap, or the 10K/min ingest rate limit | Upgrade to Pro (2M events included) or batch/reduce event volume |\n| `policy fetch error: AbortError` | Policy fetch exceeded `timeoutMs` (default 5s) | The SDK fails open to the default policy; raise `timeoutMs` or check egress to api.mastguard.io |\n| `protect() blocked but my LLM was still called` | You passed a started `Promise`, not a thunk | Pass `() => client.create(...)` — pre-call blocks then prevent the call entirely |\n\n## MastGuard SDK vs. LangSmith vs. Arize vs. Helicone\n\n| Capability | MastGuard SDK | LangSmith | Arize (Phoenix) | Helicone |\n| --- | --- | --- | --- | --- |\n| Primary job | Runtime **security + governance enforcement** | LLM tracing/evals | ML/LLM observability + evals | LLM proxy analytics/cost |\n| Pre-call blocking (call never happens) | ✅ thunk-based intercept | ❌ | ❌ | ⚠️ rate/spend limits only |\n| Threat detection (injection/exfiltration/harm) | ✅ 5 rule layers, client-side | ❌ | ⚠️ eval-time only | ❌ |\n| MCP tool-call policy + audit | ✅ `MastGuardMCPProxy` | ❌ | ❌ | ❌ |\n| Tamper-evident audit chain (SHA-256) | ✅ | ❌ | ❌ | ❌ |\n| Compliance reporting (GDPR/HIPAA/EU AI Act…) | ✅ platform-generated | ❌ | ❌ | ❌ |\n| HITL review routing | ✅ platform | ⚠️ annotation queues | ⚠️ labeling | ❌ |\n| Tracing/latency analytics | ⚠️ basic (latency, tokens) | ✅ deep | ✅ deep | ✅ deep |\n\nUse LangSmith/Arize/Helicone for debugging quality and cost; use MastGuard\nwhen an auditor, regulator, or CISO needs proof of control.\n\n## Error Handling\n\n```ts\nimport { MastGuardBlockedError } from '@auxdynamics/mastguard-agent-sdk';\n\ntry {\n  const result = await shield.protect(() => llmCall(), { sessionId });\n  // result.violations may contain 'flag'/'log' findings even when allowed\n} catch (err) {\n  if (err instanceof MastGuardBlockedError) {\n    for (const v of err.violations) {\n      console.error(`[${v.severity}] ${v.category}: ${v.description}`);\n      // v.action is 'block' | 'flag' | 'log'\n      // v.evidence contains the raw matched content\n    }\n  } else {\n    throw err;\n  }\n}\n```\n\nIn `block` mode, a policy violation throws `MastGuardBlockedError` — pre-call\nviolations throw before the LLM is invoked; post-call violations throw after,\nwithholding the response. In `monitor` mode, nothing is ever blocked —\nviolations are logged to MastGuard and returned in `result.violations`,\nletting you evaluate policy impact before enforcing it.\n\n## TypeScript\n\nFull TypeScript support is included — no `@types` package needed. CJS and ESM builds are both shipped.\n\n```ts\nimport type {\n  ShieldConfig,\n  ShieldResult,\n  ViolationRecord,\n  ToolCallRecord,\n  ProtectOptions,\n  EvaluationResult,\n  PolicyTier,\n  ShieldMode,\n  Severity,\n  ViolationAction,\n} from '@auxdynamics/mastguard-agent-sdk';\n```\n\n## Related Packages\n\nThis package handles **runtime AI security monitoring**.\n\nIf you need to integrate with the MastGuard **governance platform** (audit logs, HITL queues, webhooks, compliance dashboards), use the companion SDK:\n\n[@auxdynamics/mastguard-sdk](https://www.npmjs.com/package/@auxdynamics/mastguard-sdk)\n\n## License\n\nMIT © [AuxDynamics Inc.](https://mastguard.io)\n","readmeFilename":"README.md"}