{"_id":"@bpsecops/ai-guard","_rev":"2-d697baaec977d9f347ed81ca83418af1","name":"@bpsecops/ai-guard","dist-tags":{"latest":"0.2.6"},"versions":{"0.2.5":{"name":"@bpsecops/ai-guard","version":"0.2.5","_id":"@bpsecops/ai-guard@0.2.5","maintainers":[{"name":"bpsecops","email":"bcbcpardue@gmail.com"}],"bin":{"ai-guard":"dist/ai-guard.mjs"},"dist":{"shasum":"b4231e13be9af98d4c85f808413bf45d4b1a175f","tarball":"https://registry.npmjs.org/@bpsecops/ai-guard/-/ai-guard-0.2.5.tgz","fileCount":13,"integrity":"sha512-Tp/ivDFvO7vGOTn1pa1jHX/gGIrrbl8px2CP45oNm7dXjVc+0k9BCG5+n94MIkPZWTt4UsMvrHY4Ns1VaKan1A==","signatures":[{"sig":"MEUCIQCOY8XXHZxJe234AErcH65g7uhpWPXce3c7fG3Qqx3GyQIgfOzPMw14B7l4VhKxUEGdK+W6yis1iMeowzkwUXxcW7Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":864143},"type":"module","gitHead":"fa0a3a1c57f1ae1968eaaf4130445b07ffbceb3d","scripts":{"dev":"wxt","zip":"wxt zip","lint":"eslint src --ext .ts,.tsx","test":"vitest run","build":"wxt build","format":"prettier --write src","compile":"tsc --noEmit","build:all":"npm run build && npm run build:cli && npm run build:mcp","build:cli":"node cli/build.mjs","build:mcp":"node mcp/build.mjs","build:edge":"wxt build -b edge","test:watch":"vitest","dev:firefox":"wxt -b firefox","zip:firefox":"wxt zip -b firefox","build:firefox":"wxt build -b firefox","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"bpsecops","email":"bcbcpardue@gmail.com"},"_npmVersion":"10.8.2","description":"AI Guard stops sensitive data from being accidentally sent to AI tools. It works in three places — your browser, your terminal, and your file system.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"zod":"^3.23.8","vite":"^6.4.1","giget":"^3.1.2","react":"^18.3.1","react-dom":"^18.3.1","@vitejs/plugin-react":"^5.2.0","webextension-polyfill":"^0.12.0","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"wxt":"^0.20.20","jsdom":"^25.0.0","sharp":"^0.34.5","eslint":"^9.9.0","vitest":"^4.1.0","postcss":"^8.4.41","prettier":"^3.3.3","typescript":"^5.5.4","tailwindcss":"^3.4.10","@types/react":"^18.3.3","autoprefixer":"^10.4.20","@types/react-dom":"^18.3.0","@vitest/coverage-v8":"^4.1.0","eslint-plugin-react":"^7.35.2","@wxt-dev/module-react":"^1.2.2","@testing-library/react":"^16.0.0","@typescript-eslint/parser":"^8.3.0","eslint-plugin-react-hooks":"^4.6.2","@testing-library/user-event":"^14.5.2","@types/webextension-polyfill":"^0.10.7","@typescript-eslint/eslint-plugin":"^8.3.0"},"_npmOperationalInternal":{"tmp":"tmp/ai-guard_0.2.5_1774026793879_0.6130581087080516","host":"s3://npm-registry-packages-npm-production"}},"0.2.6":{"name":"@bpsecops/ai-guard","version":"0.2.6","type":"module","bin":{"ai-guard":"dist/ai-guard.mjs"},"scripts":{"dev":"wxt","dev:firefox":"wxt -b firefox","build":"wxt build","build:firefox":"wxt build -b firefox","build:edge":"wxt build -b edge","build:cli":"node cli/build.mjs","build:mcp":"node mcp/build.mjs","build:all":"npm run build && npm run build:cli && npm run build:mcp","zip":"wxt zip","zip:firefox":"wxt zip -b firefox","compile":"tsc --noEmit","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","lint":"eslint src --ext .ts,.tsx","format":"prettier --write src"},"dependencies":{"@modelcontextprotocol/sdk":"^1.27.1","@vitejs/plugin-react":"^5.2.0","giget":"^3.1.2","react":"^18.3.1","react-dom":"^18.3.1","vite":"^6.4.1","webextension-polyfill":"^0.12.0","zod":"^3.23.8"},"devDependencies":{"@testing-library/react":"^16.0.0","@testing-library/user-event":"^14.5.2","@types/react":"^18.3.3","@types/react-dom":"^18.3.0","@types/webextension-polyfill":"^0.10.7","@typescript-eslint/eslint-plugin":"^8.3.0","@typescript-eslint/parser":"^8.3.0","@vitest/coverage-v8":"^4.1.0","@wxt-dev/module-react":"^1.2.2","autoprefixer":"^10.4.20","eslint":"^9.9.0","eslint-plugin-react":"^7.35.2","eslint-plugin-react-hooks":"^4.6.2","jsdom":"^25.0.0","postcss":"^8.4.41","prettier":"^3.3.3","sharp":"^0.34.5","tailwindcss":"^3.4.10","typescript":"^5.5.4","vitest":"^4.1.0","wxt":"^0.20.20"},"_id":"@bpsecops/ai-guard@0.2.6","gitHead":"c0812e76b05d011d688b9da5b6af7d486f78d92b","description":"AI Guard stops sensitive data from being accidentally sent to AI tools. It works in three places — your browser, your terminal, and your file system.","_nodeVersion":"20.20.1","_npmVersion":"10.8.2","dist":{"integrity":"sha512-zcAIlYhaxKd3Q0uoYDMa+YETt8quQR97fiqhRZrEuH5ZVeUVfP7rA8Xc3YHWWUb0lBWoi2+mgmAPVX3eUIGv5w==","shasum":"a8a31b0017f9f27582c8ac7cfc812270cfe0bc1c","tarball":"https://registry.npmjs.org/@bpsecops/ai-guard/-/ai-guard-0.2.6.tgz","fileCount":10,"unpackedSize":827969,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDuft5pDge62guh9tmH1/5az9F/yWNlgCBfQljM2EXM0AIgFE4CoB8TdzedEYvIcErJ+d9PP7FB6qfTmEasAZgFVGQ="}]},"_npmUser":{"name":"bpsecops","email":"bcbcpardue@gmail.com"},"directories":{},"maintainers":[{"name":"bpsecops","email":"bcbcpardue@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ai-guard_0.2.6_1774034654118_0.8782681516151969"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-20T17:13:13.777Z","modified":"2026-03-20T19:24:14.469Z","0.2.5":"2026-03-20T17:13:14.043Z","0.2.6":"2026-03-20T19:24:14.346Z"},"description":"AI Guard stops sensitive data from being accidentally sent to AI tools. It works in three places — your browser, your terminal, and your file system.","maintainers":[{"name":"bpsecops","email":"bcbcpardue@gmail.com"}],"readme":"# AI Guard\n\nAI Guard stops sensitive data from being accidentally sent to AI tools. It works in three places — your browser, your terminal, and your file system.\n\n**Browser extension** — intercepts messages before you send them on ChatGPT, Claude, Gemini, and more. If sensitive data is detected, it blocks submission and shows you exactly what it found.\n\n**CLI tool** — wraps your AI command-line tools (claude, chatgpt, gemini, etc.) and scans your prompt before it reaches the model. If something sensitive is found, it warns you and blocks the command.\n\n**File protection** — prevents AI tools from reading files that contain secrets. For all tools (aider, cursor, claude, etc.), AI Guard scans any files you pass as arguments before the tool launches. For Claude Code specifically, it also intercepts file reads mid-session, blocks dangerous bash commands (`env`, `printenv`, `git log -p`, direct reads of `~/.aws/credentials`, `~/.ssh/id_rsa`, and more), and scans the output of every bash command before it reaches the model — catching secrets that would otherwise slip through via `git diff`, `docker inspect`, `kubectl get secret`, and similar commands.\n\n---\n\n## What it catches\n\n- **Credentials** — API keys, tokens, passwords, private keys (AWS, GitHub, Stripe, Slack, and more)\n- **PII** — Social Security Numbers, email addresses, phone numbers, passport numbers\n- **Financial** — Credit card numbers, bank account and routing numbers\n- **Health** — Medical record numbers, diagnoses, medication names\n- **Code secrets** — Hardcoded passwords, `.env` files, Django `SECRET_KEY`\n\n---\n\n## Browser Extension\n\nThe extension watches what you type on AI websites. When you hit Send, it scans your message first. If something sensitive is found, it blocks the submission and shows you exactly what it caught — you can then edit your message or choose to send anyway.\n\n**Supported sites:** ChatGPT, Claude, Gemini, Copilot, Perplexity, Brave Leo\n\n**Warning card** — blocked submission with details on what was found:\n\n![AI Guard warning card](docs/extension-screenshot.png)\n\n**Popup** — toggle protection on/off or pause monitoring:\n\n![AI Guard popup](docs/popup.png)\n\n**Dashboard** — track detections, blocked submissions, and overrides:\n\n![AI Guard dashboard](docs/dashboard.png)\n\n**Settings** — configure detection categories and actions per category:\n\n![AI Guard settings](docs/settings-categories.png)\n\n**Custom keywords** — add your own terms to watch for (plain text or regex):\n\n![AI Guard custom keywords](docs/settings-custom.png)\n\n### Install\n\n**Download the latest release (no Node.js required)**\n\n1. Go to the [Releases page](https://github.com/bpSecOps/ai-guard/releases)\n2. Download the zip for your browser:\n   - `ai-guard-chrome-vX.X.X.zip` — Chrome, Edge, or Brave\n   - `ai-guard-firefox-vX.X.X.zip` — Firefox\n3. Unzip the file\n\n**Chrome / Edge**\n1. Go to `chrome://extensions`\n2. Enable **Developer mode** (top right)\n3. Click **Load unpacked** → select the unzipped folder\n\n**Brave**\n1. Go to `brave://extensions`\n2. Enable **Developer mode** (top right)\n3. Click **Load unpacked** → select the unzipped folder\n\n**Firefox**\n1. Go to `about:debugging` → **This Firefox**\n2. Click **Load Temporary Add-on**\n3. Select `manifest.json` inside the unzipped folder\n\n<details>\n<summary>Build from source</summary>\n\n> Requires Node.js 18+\n\n```bash\ngit clone https://github.com/bpSecOps/ai-guard.git\ncd ai-guard\nnpm install\nnpm run build\n```\n\nThen load the `.output/chrome-mv3` folder (Chrome/Brave) or `.output/firefox-mv2/manifest.json` (Firefox) as above.\n</details>\n\n---\n\n## CLI\n\nThe CLI tool scans prompts before they reach your AI tool. Add a shell wrapper once and it works automatically in the background — you never have to think about it.\n\n### Install\n\n```bash\nnpm install -g @bpsecops/ai-guard\n```\n\n> Requires Node.js 18+\n\n### Set up shell wrappers\n\nRun the one-time setup command:\n\n```bash\nai-guard setup\n```\n\nThis installs shell wrappers for claude, chatgpt, gemini, copilot, cursor, and aider into your `~/.zshrc` and `~/.bashrc`. Then reload your shell:\n\n```bash\nsource ~/.zshrc   # or source ~/.bashrc\n```\n\n### How it works\n\nFrom this point on, just use your AI tools normally. AI Guard runs silently in the background.\n\n```bash\nclaude \"explain this function\"\n# ✅ Clean — claude launches normally\n\nclaude \"my Stripe key is sk_live_abc123...\"\n# 🚫 Blocked — AI Guard warns you before claude launches\n```\n\nIf something is detected you'll see a warning card showing exactly what was found. Fix your message and try again.\n\n---\n\n## File Protection\n\nAI Guard protects you from accidentally feeding secrets into AI tools through three mechanisms — one that fires when you pass files at launch, one that intercepts file reads mid-session, and one that scans bash command output before it reaches the model.\n\n### Launch-time file scanning (all tools)\n\nThe shell wrappers installed by `ai-guard setup` automatically scan any files you pass as arguments before the AI tool launches. This works for every supported tool:\n\n```bash\naider .env secrets.py\n# 🚫 Blocked — AI Guard found credentials in .env before aider launched\n\ncursor --read config/database.yml\n# 🚫 Blocked — AI Guard found a password before cursor launched\n\nclaude --file deployment-notes.txt\n# ✅ Clean — claude launches normally\n```\n\nIf a file contains critical secrets it is blocked outright. Warnings let the command through but tell you what was found.\n\n### Mid-session file protection (Claude Code)\n\nClaude Code has a hook system that lets AI Guard intercept file reads that happen during a conversation — not just at launch. When Claude tries to read a `.env` file, private key, or any file containing credentials mid-session, AI Guard blocks the read, tells you exactly what it found, and asks if you want to proceed.\n\n```bash\n# Inside a Claude Code session:\n# You: \"read my .env file\"\n# 🚫 AI Guard blocked this read — .env contains: Generic credential in key=value,\n#    AWS Access Key. Do you want to allow it?\n```\n\n### Bash command protection (Claude Code)\n\nAI Guard also intercepts bash commands that could expose secrets — both before they run and after. This catches the cases that file scanning misses entirely.\n\n**Blocked before execution:**\n\n| Command | Why |\n|---|---|\n| `env` / `printenv` | Dumps all environment variables including API keys |\n| `cat ~/.aws/credentials` | AWS credentials file |\n| `cat ~/.ssh/id_rsa` | Private SSH key |\n| `cat ~/.netrc` / `~/.npmrc` / `~/.pypirc` | Auth tokens |\n| `cat ~/.docker/config.json` | Docker registry credentials |\n| `git log -p` / `git log --patch` | Git history may contain previously-committed secrets |\n\n```bash\n# Claude tries to run: env\n# 🚫 AI Guard blocked this command. Running 'env' dumps all environment\n#    variables, which likely include API keys and tokens.\n\n# Claude tries to run: git log -p\n# 🚫 AI Guard blocked 'git log -p'. Showing full git diffs may expose\n#    secrets that were previously committed and later removed.\n```\n\n**Scanned after execution:**\n\nEvery bash command output is scanned before Claude sees it. If secrets appear in the output — from `git diff`, `docker inspect`, `kubectl get secret`, or anything else — Claude is warned not to repeat the values verbatim.\n\n```bash\n# Claude runs: docker inspect my-container\n# ⚠️  AI Guard WARNING: This command output contains high-risk sensitive\n#    data (Generic credential in key=value). Do NOT reproduce these values.\n```\n\nIf AI Guard blocks a command you actually need, tell Claude to proceed and it will be allowed through once.\n\n### Setup\n\nAll three protections are installed by a single command:\n\n```bash\nai-guard setup\n```\n\nThis installs the shell wrappers for all tools and registers all three Claude Code hooks automatically.\n\n---\n\n## MCP Server\n\nAI Guard includes an MCP (Model Context Protocol) server that adds file protection to any MCP-compatible AI tool — Cursor, Zed, Continue, and others.\n\nThe MCP server exposes two tools:\n\n- **`read_file`** — scans the file before returning its contents. Critical findings are blocked outright; high/medium findings return the content with a warning prepended.\n- **`read_file_force`** — reads without scanning. Use this only when the user has explicitly confirmed they want to proceed.\n\n### Install\n\nBuild the MCP server:\n\n```bash\nnpm install -g github:bpSecOps/ai-guard\nai-guard build:mcp   # or: node mcp/build.mjs from the repo\n```\n\nThis produces `dist/ai-guard-mcp.mjs`.\n\n### Claude Code\n\n```bash\nclaude mcp add ai-guard node /path/to/ai-guard/dist/ai-guard-mcp.mjs --scope user\n```\n\n> Note: Claude Code users also get the PreToolUse hook installed by `ai-guard setup`, which intercepts native file reads at the OS level and cannot be bypassed by the model. The MCP server adds a second layer on top.\n\n### Cursor\n\nAdd to your Cursor MCP config (`~/.cursor/mcp.json` or the project-level `.cursor/mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"ai-guard\": {\n      \"command\": \"node\",\n      \"args\": [\"/path/to/ai-guard/dist/ai-guard-mcp.mjs\"]\n    }\n  }\n}\n```\n\n### Zed\n\nAdd to your Zed `settings.json` under `\"context_servers\"`:\n\n```json\n{\n  \"context_servers\": {\n    \"ai-guard\": {\n      \"command\": {\n        \"path\": \"node\",\n        \"args\": [\"/path/to/ai-guard/dist/ai-guard-mcp.mjs\"]\n      }\n    }\n  }\n}\n```\n\n### Continue\n\nAdd to your Continue `config.json` under `\"mcpServers\"`:\n\n```json\n{\n  \"mcpServers\": [\n    {\n      \"name\": \"ai-guard\",\n      \"command\": \"node\",\n      \"args\": [\"/path/to/ai-guard/dist/ai-guard-mcp.mjs\"]\n    }\n  ]\n}\n```\n\n### How it works\n\nWhen a supported tool calls `read_file`, AI Guard scans the file using the same detection engine as the browser extension and CLI. If something critical is found, the read is blocked and the tool is instructed to tell you what was found and ask whether to proceed. If you confirm, the tool can call `read_file_force` with the same path to allow the read.\n\n```\n# AI asks to read .env\nread_file(\"/home/user/project/.env\")\n\n🔴 AI Guard blocked this read.\n\nThe file `.env` contains critical sensitive data:\n\n  [!!!] AWS Access Key ID — AK********LE\n  [!!!] .env file content — AW********DE\n\nTell the user what was found and ask if they want to proceed.\nIf they confirm, use `read_file_force` with the same path to allow the read.\n```\n\n---\n\n## Development\n\n```bash\nnpm install\nnpm test               # Run test suite\nnpm run dev            # Chrome dev server with hot reload\nnpm run build          # Build for Chrome\nnpm run build:firefox  # Build for Firefox\nnpm run build:cli      # Build CLI binary\nnpm run build:mcp      # Build MCP server\nnpm run build:all      # Build everything\n```\n","readmeFilename":"README.md"}