alpha
Login
or
Join now
jenchan.biz
/
badger
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
Prompt-injection defenses for LLM agents — fetch interception, output sanitization, session inspection.
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
Overview
Issues
Pulls
Pipelines
badger
/
packages
/
fetch
/
evals
/
sanitization
/
at
main
4 files
Jen Chan
badger: trim dead weight, harden URL validation + sanitization eval
3mo ago
532bef51
mock-server.ts
badger: prompt-injection defenses for LLM agents pnpm monorepo, published as @usrrname/badger-*: - badger-fetch: MCP server + Claude/OpenCode hooks that intercept agent web fetches, guard requests (HTTPS/SSRF/rate-limit), and enforce a two-signal pass/neutralize/block policy on responses - badger-response: zero-dependency library detecting prompt-injection compromise, exfiltration, and obfuscation in tool output - badger-inspector: terminal UI for Claude Code / OpenCode session transcripts, flagging compromise inline Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 months ago
promptfooconfig.yaml
badger: prompt-injection defenses for LLM agents pnpm monorepo, published as @usrrname/badger-*: - badger-fetch: MCP server + Claude/OpenCode hooks that intercept agent web fetches, guard requests (HTTPS/SSRF/rate-limit), and enforce a two-signal pass/neutralize/block policy on responses - badger-response: zero-dependency library detecting prompt-injection compromise, exfiltration, and obfuscation in tool output - badger-inspector: terminal UI for Claude Code / OpenCode session transcripts, flagging compromise inline Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 months ago
provider.ts
badger: trim dead weight, harden URL validation + sanitization eval Over-engineering trim (-318 lines): - delete 3 unused follow-*.sim.mjs scratch simulators (inspector) - fold injection-corpus.ts into its only consumer (the precision test) - fold base64-views.ts into normalize-views.ts; drop the duplicate Base64View interface (identical shape to DecodedView) fetch `url` validation via native zod (zod.dev/api#urls): - replace the ad-hoc string check with a union of two z.url() schemas — https for public hosts, http only for loopback - share one LOOPBACK_HOSTNAME definition between the schema and validateUrl sanitization eval no longer flakes: - provider reuses a mock server left by a prior run instead of EADDRINUSE-crashing, and kills it on exit so it stops leaking - now a clean 15/15 Naming: audit path -> .badger, secure_fetch tool -> badger_fetch (test updated to match). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 months ago
tests.yaml
badger: prompt-injection defenses for LLM agents pnpm monorepo, published as @usrrname/badger-*: - badger-fetch: MCP server + Claude/OpenCode hooks that intercept agent web fetches, guard requests (HTTPS/SSRF/rate-limit), and enforce a two-signal pass/neutralize/block policy on responses - badger-response: zero-dependency library detecting prompt-injection compromise, exfiltration, and obfuscation in tool output - badger-inspector: terminal UI for Claude Code / OpenCode session transcripts, flagging compromise inline Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 months ago