{"_id":"@consulalialpric/llm-antivirus","_rev":"2-15ddc15a3e82838546f44e4ee673ce70","name":"@consulalialpric/llm-antivirus","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@consulalialpric/llm-antivirus","version":"0.1.0","keywords":["llm","security","claude","agent","antivirus","safety"],"author":{"name":"consulalialpric"},"license":"MIT","_id":"@consulalialpric/llm-antivirus@0.1.0","maintainers":[{"name":"consulalialpric","email":"consulalialpric@atomicmail.io"}],"homepage":"https://github.com/consulalialpric/llm-antivirus#readme","bugs":{"url":"https://github.com/consulalialpric/llm-antivirus/issues"},"bin":{"llm-antivirus":"dist/cli.js"},"dist":{"shasum":"c31b2563a7dc66294df693a1502f8dfa5e55e1cb","tarball":"https://registry.npmjs.org/@consulalialpric/llm-antivirus/-/llm-antivirus-0.1.0.tgz","fileCount":13,"integrity":"sha512-PIBXMMIP5OnYoQXsWYA1VpgHKD3LUNFXbEc8cwmr18TxYzglKoq9RWAvD6w2XC0PIHXJjg2/Ub9dShqtF+SJlg==","signatures":[{"sig":"MEQCIFUORT3fH/BClmeIzhzHTa+rJfgSZ2RA1OAgLJSEBtfWAiAqevnpnS8u5z9EcddCmS+PsLQNJjchwh4JRAsDxy/I1g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45799},"type":"module","engines":{"node":">=20.0.0"},"gitHead":"66af4849a58e053c18b80ba222516ba0cebfd8bc","scripts":{"dev":"tsx src/cli.ts","test":"vitest","build":"tsc && npm run copy-templates","copy-templates":"mkdir -p dist/hooks/templates && cp src/hooks/templates/* dist/hooks/templates/"},"_npmUser":{"name":"consulalialpric","email":"consulalialpric@atomicmail.io"},"repository":{"url":"git+https://github.com/consulalialpric/llm-antivirus.git","type":"git"},"_npmVersion":"11.7.0","description":"Security layer for LLM-driven code agents - blocks dangerous operations before they execute","directories":{},"_nodeVersion":"22.16.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","vitest":"^1.2.0","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/llm-antivirus_0.1.0_1769783299687_0.4702472080728095","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@consulalialpric/llm-antivirus","version":"0.1.1","description":"Security layer for LLM-driven code agents - blocks dangerous operations before they execute","type":"module","bin":{"llm-antivirus":"dist/cli.js"},"engines":{"node":">=20.0.0"},"scripts":{"build":"tsc && npm run copy-templates","copy-templates":"mkdir -p dist/hooks/templates && cp src/hooks/templates/* dist/hooks/templates/","watch:tsc":"tsc --watch --preserveWatchOutput","watch:assets":"nodemon --watch src/hooks/templates --ext sh --exec \"npm run copy-templates\"","dev":"concurrently --kill-others-on-fail --prefix \"[{name}]\" --names \"tsc,assets\" \"npm:watch:*\"","test":"vitest"},"keywords":["llm","security","claude","agent","antivirus","safety"],"author":{"name":"consulalialpric"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/consulalialpric/llm-antivirus.git"},"homepage":"https://github.com/consulalialpric/llm-antivirus#readme","dependencies":{"chalk":"^4.1.2","commander":"^12.1.0","ora":"^5.4.1"},"devDependencies":{"@types/node":"^20.11.0","concurrently":"^9.2.1","nodemon":"^3.1.11","tsx":"^4.7.0","typescript":"^5.3.3","vitest":"^1.2.0"},"gitHead":"3275498559ae75801dc1740fa7246a408a1dbc80","_id":"@consulalialpric/llm-antivirus@0.1.1","bugs":{"url":"https://github.com/consulalialpric/llm-antivirus/issues"},"_nodeVersion":"22.16.0","_npmVersion":"11.7.0","dist":{"integrity":"sha512-5dz3i5A59f/OUTHipxiz4fz52h/Eh7gR/bxuRX25nOZgi8z0mzRxKqHVpRGbG9lK6g/pN/AYP9MByQ+pMW3xVw==","shasum":"dc8c819ae6b8d19f69c431acb36dc6b7851b95ba","tarball":"https://registry.npmjs.org/@consulalialpric/llm-antivirus/-/llm-antivirus-0.1.1.tgz","fileCount":39,"unpackedSize":159176,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICL7XeHlp5Dn6hd3J061et6RzzoUTUkx2QimszGZZHO0AiEAtM0sYvkGoiQ4qRpOUwDREL31/y0QlM7G0/kCJSpO6LA="}]},"_npmUser":{"name":"consulalialpric","email":"consulalialpric@atomicmail.io"},"directories":{},"maintainers":[{"name":"consulalialpric","email":"consulalialpric@atomicmail.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/llm-antivirus_0.1.1_1769962911733_0.7793151373051932"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-30T14:28:19.579Z","modified":"2026-02-01T16:21:52.009Z","0.1.0":"2026-01-30T14:28:19.846Z","0.1.1":"2026-02-01T16:21:51.879Z"},"bugs":{"url":"https://github.com/consulalialpric/llm-antivirus/issues"},"author":{"name":"consulalialpric"},"license":"MIT","homepage":"https://github.com/consulalialpric/llm-antivirus#readme","keywords":["llm","security","claude","agent","antivirus","safety"],"repository":{"type":"git","url":"git+https://github.com/consulalialpric/llm-antivirus.git"},"description":"Security layer for LLM-driven code agents - blocks dangerous operations before they execute","maintainers":[{"name":"consulalialpric","email":"consulalialpric@atomicmail.io"}],"readme":"# LLM Antivirus\n\nA security layer for Claude Code that blocks dangerous operations before they execute. Protects against credential leakage, destructive commands, PII exposure, and prompt injection attacks.\n\n## Why?\n\nLLM-driven development tools can inadvertently:\n- Expose API keys and credentials from training data\n- Execute destructive shell commands (`rm -rf /`)\n- Leak sensitive information like SSNs or credit cards\n- Fall victim to prompt injection attacks\n\nLLM Antivirus intercepts tool calls via Claude Code hooks and blocks threats before execution.\n\n## Quick Start\n\n```bash\nnpx llm-antivirus init\n```\n\nThat's it. Zero configuration required.\n\n## Requirements\n\n- Node.js >= 20.0.0\n- Claude Code project (`.claude/` directory)\n- `jq` for JSON parsing (`brew install jq` on macOS)\n\n## What It Detects\n\n### Layer 1: Sensitive Files\nBlocks access to files like `.env`, `.aws/credentials`, `.ssh/id_rsa`, `secrets.json`\n\n### Layer 2: Credentials\nDetects 9 credential patterns:\n- AWS Access Keys (`AKIA...`)\n- GitHub Tokens (`ghp_...`)\n- OpenAI API Keys (`sk-...`)\n- Slack Tokens (`xox[pboa]-...`)\n- Stripe Keys (`sk_live_...`, `sk_test_...`)\n- SendGrid, Twilio, Google API keys\n- Bearer tokens\n\n### Layer 3: Private Keys\nCatches PEM-format private keys (RSA, DSA, EC, OpenSSH)\n\n### Layer 4: Dangerous Commands\nBlocks shell commands like:\n- `rm -rf` with force+recursive flags\n- `curl | bash` (remote code execution)\n- `chmod 777` (overly permissive)\n- `dd of=/dev/*` (disk writes)\n- `mkfs` (filesystem formatting)\n\n### Layer 5: PII\nDetects SSNs and credit card numbers with format validation\n\n### Layer 6: Prompt Injection (Warning)\nAlerts on suspicious phrases without blocking:\n- \"ignore previous instructions\"\n- \"disregard all prior\"\n- Jailbreak attempts (\"DAN mode\", \"developer mode\")\n- System prompt leakage indicators\n\n## Configuration\n\n### Allowlist & Blocklist\n\nCreate config files to customize detection:\n\n**Global config** (`~/.llm-av/config.json`):\n```json\n{\n  \"allowlist\": {\n    \"paths\": [\"tests/fixtures/*\"],\n    \"patterns\": [\"test_credential_[a-z]+\"]\n  },\n  \"blocklist\": {\n    \"paths\": [\"production/secrets/*\"],\n    \"patterns\": [\"CUSTOM_SECRET_[A-Z0-9]+\"]\n  }\n}\n```\n\n**Project config** (`.llm-av/config.json`):\nSame structure. Project settings extend global settings.\n\n### Escape Hatch\n\nFor testing or emergencies:\n```bash\nLLMAV_SKIP=1 claude\n```\nThis bypasses all checks (logged to audit trail).\n\n## Audit Trail\n\nAll blocked operations are logged to `.llm-av/audit.json` in JSON Lines format:\n\n```json\n{\"timestamp\":\"2026-01-30T10:15:30Z\",\"severity\":\"HIGH\",\"layer\":\"credentials\",\"pattern\":\"AWS Access Key\",\"tool\":\"Write\",\"blocked\":true}\n```\n\n## How It Works\n\nLLM Antivirus installs Claude Code hooks that intercept tool calls:\n\n```\nClaude Code Tool Call\n        ↓\n  PreToolUse Hook\n        ↓\n┌───────────────────┐\n│ security-check.sh │\n│  Layer 1-5 check  │\n└───────┬───────────┘\n        │\n   ┌────┴────┐\n   │         │\nExit 0    Exit 2\n(allow)   (block)\n   │         │\n   ▼         ▼\nExecute   Show error\n  tool    to user\n```\n\nDetection runs in < 10ms using optimized Bash pattern matching.\n\n## OWASP LLM Vulnerabilities Addressed\n\n| Vulnerability | Coverage |\n|---------------|----------|\n| LLM06: Sensitive Information Disclosure | Layers 1-3, 5 |\n| LLM08: Excessive Agency | Layer 4 |\n| LLM07: System Prompt Leakage | Layer 6 |\n\n## Development\n\n```bash\n# Install dependencies\nnpm install\n\n# Build\nnpm run build\n\n# Run locally\nnpm run dev init\n```\n\n### Project Structure\n\n```\nsrc/\n├── cli.ts                 # CLI entry point\n├── commands/\n│   └── init.ts           # Initialization logic\n├── hooks/\n│   ├── installer.ts      # Hook installation\n│   └── templates/\n│       └── security-check.sh  # Detection script (944 LOC)\n├── rules/\n│   └── default-rules.ts  # Pattern definitions\n└── utils/\n    └── claude-detector.ts # Project detection\n```\n\n## Limitations\n\n- Pattern-based detection can be bypassed with obfuscation\n- Does not prevent training-time attacks (poisoning)\n- Novel attack patterns may not be detected\n- Prompt injection defense is warning-only (high false positive risk)\n\nThis tool reduces attack surface but does not eliminate risk entirely.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}