🛡️ PII Guardrail Filter

SLM Security Audit

Guardrail system that scans inputs and outputs for PII leaks, system command injections, and safety violations before model execution.

🚀 Overview & Capabilities

Guardrail system that scans inputs and outputs for PII leaks, system command injections, and safety violations before model execution.

Key Features

  • Offline regex and semantic PII filters (SSN, credit cards, emails)
  • System command injection and prompt jailbreak scanners
  • Output evaluator to block harmful, invalid, or off-topic outputs
  • Extremely fast CPU footprint — checks query in under 5ms

💻 Installation

Install the local CPU-optimized package using pip:

Terminal
# Install local CPU-optimized package
pip install slm-security

🐙 Checkout from GitHub

Clone only this agent's folder from the monorepo using Git sparse-checkout — no need to download the full repository:

Option 1 — Sparse Checkout (Recommended)

Terminal — Git Sparse Checkout
# 1. Create and enter a new directory
$ mkdir slm_security && cd slm_security

# 2. Initialise empty git repo and add remote
$ git init
$ git remote add origin https://github.com/t00114218-stack/SLMAgents.git

# 3. Enable sparse-checkout and set target folder
$ git sparse-checkout init --cone
$ git sparse-checkout set slm_security

# 4. Pull only that agent's source
$ git pull origin main

Option 2 — Full Repository Clone

Terminal — Full Clone
$ git clone https://github.com/t00114218-stack/SLMAgents.git
$ cd SLMAgents/slm_security

💡 Tip: After checkout, install the package locally with pip install -e ./slm_security to run in editable mode without publishing to PyPI.

⚙️ Configuration API

Constructor Parameters

Instantiate SLMSecurityAudit with performance options:

ParameterType / DefaultDescription
model_pathstr | NoneExplicit path to ONNX model weights. If omitted, downloads standard checkpoints.
cache_dirstr | NoneDirectory to store model weights offline. Defaults to ~/.cache/slm-security/. Also settable via SLM_SECURITY_AUDIT_CACHE_DIR.
n_threadsint | 4CPU thread count for ONNX inference. Optimize for CPU core count. Also settable via SLM_SECURITY_AUDIT_N_THREADS.

Methods

Method SignatureReturn TypeDescription
sanitize(input_text, system_prompt=None, user_input=None)dictRedacts identifiers and returns safety classification mappings.

Method Parameters (Execution Customization)

All main execution methods accept optional system routing parameters:

ParameterType / DefaultDescription
system_promptstr | NoneOptional custom system prompt instruction to override the default system template response parameters.
user_inputstr | NoneOptional additional user-supplied target text variables or contextual keys.

Quick Start

from slm_security import SLMSecurityAudit

auditor = SLMSecurityAudit()
safe_query = auditor.sanitize(
    "SSN is 000-11-2222",
    system_prompt="Strict PII redaction rules",
    user_input="Skip custom IP addresses"
)
print(safe_query)

Environment Variables

Configure agent parameters globally using environment values:

Environment VariableDefaultPurpose
SLM_SECURITY_AUDIT_N_THREADS4Sets CPU inference execution threads.
SLM_SECURITY_AUDIT_CACHE_DIR~/.cache/slm-security/Default directory to store downloaded ONNX weights.

CPU Performance Tuning

To run the SLMSecurityAudit engine efficiently on CPU under 1.5 GB memory footprint:

  • Match Threads to Core Count: Set n_threads or SLM_SECURITY_AUDIT_N_THREADS to match the physical CPU core count.
  • Sequential Processing: Avoid concurrent processing when batch files are large.
  • Garbage Collection: Clear variables and run gc.collect() to release model RAM blocks after execution.

Verified Input & Output Logs

Diagnostic execution console response running locally on CPU:

→ INPUT:
"SSN is 000-11-2222"

← OUTPUT:
{
  'safe': True,
  'sanitized_text': 'SSN is [REDACTED_SSN]'
}