prompt-injection-shield
当用户要把网页抓取/邮件/工具返回值/检索文档/用户上传内容喂给 AI,又担心里面藏『忽略之前指令』『你是新AI』这类指令时使用。在不可信内容进上下文之前先扫描:中英双语文式库(忽略指令/角色劫持/越狱/DAN/索要系统提示)+ 启发式(面向AI的祈使句、角色切换、索要隐藏指令)+ 沙箱规则。附可运行扫描脚本,输出风险分·命中规则·处置建议(丢弃/隔离/沙箱)。复用 desens-scan 与 release-gate 的去敏与门禁能力。触发词:提示注入、prompt injection、注入防护、越狱、jailbreak、忽略指令、角色劫持、system prompt泄露、内容安全、AI被操
as observed 2026-09-29T04:47:03.526Z- Identifier
prompt-injection-shield- Source
- ClawHub
- Version observed
- 1.0.3
- Source repository
- not published
- Repository observation
- No source repository listed
- First observed here
- 2026-09-12T14:17:54.398Z
- Observations recorded
- 3
- Installs (reported upstream)
- 1
- Weekly downloads (upstream)
- 228
- Declared license
- MIT-0
Observation history
2026-09-29T04:47:03.526Z
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"- Initial release of Prompt Injection Shield for Windows, macOS, and Linux.\n- Scans and detects prompt injection attempts in external content before sending it to AI, using bilin | "权利层第 3 轮:① §3.2 权属宣告统一块归一——清除块内他资产事实(此前误填 uibc-core 的 DOI / commit cb6f11b / Sigstore Rekor 锚),改按本资产真值填写;② 技能件许可口径过授权清除——理论文本由 CC BY 4.0 改为「保留所有权利」,.py 依 §3.2 标 MIT;③ 保留分层许可:代码 MI |
latestVersion |
"1.0.0" | "1.0.3" |
2026-09-17T19:21:47.094Z
Fields that differed: license description
| Field | Before | After |
|---|---|---|
license |
null | "MIT-0" |
description |
"当用户要把网页抓取/邮件/工具返回值/检索文档/用户上传内容喂给 AI,又担心里面藏『忽略之前指令』『你是新AI』这类指令时使用。在不可信内容进上下文之前先扫描:中英双语文式库(忽略指令/角色劫持/越狱/DAN/索要系统提示)+ 启发式(面向AI的祈使句、角色切换、索要隐藏指令)+ 沙箱规则。附可运行扫描脚本,输出风险分·命中规则·处置建议(丢弃/隔离/沙 | null |
Correction
If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.