$npx skillfedfor your agent

llm-guard

LLM-Guard is a comprehensive tool designed to fortify the security of Large Language Models (LLMs). By offering sanitization, detection of harmful language, prevention of data leakage, and resistance against prompt injection attacks, LLM-Guard ensures that your interactions with LLMs remain safe and secure.

SkipPyPI SecurityReleased May 2025211.8K downloads / moPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — llm_guard-0.3.16-py3-none-any.whl
v0.3.16 · released 2025-05-19 · Python <3.13,>=3.10 · 12 runtime deps: bc-detect-secrets, faker, fuzzysearch, json-repair, nltk, presidio-analyzer, presidio-anonymizer, regex

No—not for new projects. While the package is feature-rich and has low install friction, its abandoned status (archived repo, no commits since 2026-07-08) is disqualifying for security-sensitive work. An unmaintained firewall cannot be trusted to defend against evolving threats. Consider it only if you have a specific, time-bounded use case and can fork and maintain it yourself.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or higher (capped below 3.13).
  • Heavy dependencies like torch and transformers may require significant disk space and download time.
  • Low install friction with a pure-Python wheel, but the package is abandoned as of the latest commit on 2026-07-08.

License · maintenance · safety

(unclear) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it legally straightforward to adopt—though the abandoned status means no upstream security patches or maintenance.

last release 2025-05-19 (452 days) · last repo commit 2026-07-08 · 3,202 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 211,788 downloads/mo, #9,474 on PyPI

Verify before relying

pip install llm-guard

from llm_guard import scan_prompt
result = scan_prompt("user input here")
  • Whether the abandoned status affects real-world security scanning reliability or if the final release remains effective for current threat models
  • Performance characteristics and latency of scanning operations under production load
  • Compatibility of the 12 runtime dependencies with recent versions of torch, transformers, and other ML libraries
Same gist for agents: .md · .json

What it is and what it does

LLM Guard is a security toolkit that scans both user inputs (prompts) and model outputs to detect and mitigate threats in Large Language Model interactions. It offers multiple scanning strategies including prompt injection detection, PII anonymization, secret detection, toxicity analysis, and output validation for harmful content, code injection, and factual consistency. The package integrates with popular LLM APIs and is designed for production deployment.

The package depends on 12 runtime libraries spanning NLP (nltk, transformers, tiktoken), data anonymization (presidio-analyzer, presidio-anonymizer, faker), and ML inference (torch). However, the project is now abandoned—its repository is archived and the last commit was 2026-07-08, meaning no new features, bug fixes, or security patches will be released. For teams considering adoption, this means relying on a static codebase for an inherently security-sensitive tool.

Use it for

  • Scan user prompts before sending to a production LLM API to block prompt injection and data exfiltration attempts
  • Anonymize personally identifiable information in user inputs and deanonymize model outputs to comply with privacy requirements
  • Detect and filter toxic, biased, or harmful language in both prompts and LLM responses
  • Validate LLM outputs for code injection, malicious URLs, and factual consistency before returning to users
  • Enforce organizational policies by banning specific topics, competitors, or substrings in LLM interactions

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No—not for new projects.

While the package is feature-rich and has low install friction, its abandoned status (archived repo, no commits since 2026-07-08) is disqualifying for security-sensitive work. An unmaintained firewall cannot be trusted to defend against evolving threats. Consider it only if you have a specific, time-bounded use case and can fork and maintain it yourself.

Install

llm-guard on PyPI

Before you install

Low install friction with a pure-Python wheel, but the package is abandoned as of the latest commit on 2026-07-08. The 12 runtime dependencies include heavy libraries (torch, transformers, tiktoken) that will pull in substantial downloads; base functionality requires fewer, with advanced features auto-installing as needed.

Requires Python 3.10 or higher (capped below 3.13). Heavy dependencies like torch and transformers may require significant disk space and download time.

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it legally straightforward to adopt—though the abandoned status means no upstream security patches or maintenance.

Quickstart

pip install llm-guard

from llm_guard import scan_prompt
result = scan_prompt("user input here")

Verify before relying

  • Whether the abandoned status affects real-world security scanning reliability or if the final release remains effective for current threat models
  • Performance characteristics and latency of scanning operations under production load
  • Compatibility of the 12 runtime dependencies with recent versions of torch, transformers, and other ML libraries

Package facts

LicenseNot declared unclear
Python supportCapped below the current Python release <3.13,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
12 packages
bc-detect-secretsfakerfuzzysearchjson-repairnltkpresidio-analyzerpresidio-anonymizerregextiktokentorchtransformersstructlog
MaintenanceAbandoned 452 days since the last release
Last repo commit repository archived
First released
Downloads211,788 / month, #9,474 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12

Evidence: llm_guard-0.3.16-py3-none-any.whl

Tags

Capabilities
llm security scanningprompt injection detectionpii detection for language modelsllm content filteringadversarial prompt defensellm firewallharmful content detection
Topics
llm-securityprompt-injectionpii-detection
PyPI keywords
llmlanguage modelsecurityadversarial attacksprompt injectionprompt leakagePII detectionself-hardeningfirewall

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “llm security scanning”

  • llm-guardLLM Guard provides input and output scanning for Large Language…
  • cisco-ai-mcp-scannerScans MCP (Model Context Protocol) servers and tools for security…
  • cisco-ai-skill-scannerScans AI Agent Skills for prompt injection, data exfiltration, and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also datarobot-moderations · garak · deepteam · guardrails-ai · plugin-scanner · hol-guard · pydantic-ai-shields · codeshield · toolguard · zizmor

Further reading