by agent-threat-rules · v0.1.0
Local AI-agent / prompt-injection threat detection powered by the open Agent Threat Rules (ATR) engine. Scans text against the ATR ruleset and returns a verdict (pass / flag / block) with matched rule IDs, category, and confidence. Runs fully local — no data leaves the host.
This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.
Available inside your emploidai workspace after installation.
Available inside your emploidai workspace after installation.
A Dify Tool plugin that scans text for AI-agent security threats using the open Agent Threat Rules (ATR) engine — prompt injection, tool poisoning, credential exfiltration, and skill supply-chain attacks. Runs fully local (no API key, no data leaves the host).
Scan for agent threats (scan) — input input_text, returns:
{
"flagged": true,
"verdict": "block",
"matched_count": 2,
"detections": [
{ "rule_id": "ATR-2026-00030", "title": "...", "severity": "critical", "confidence": "0.95" }
]
}
Optional block_severities (default critical,high) controls which severities
count as flagged. Place the tool before an Agent/LLM node to gate input, or
after it to scan output — branch on flagged / verdict with an IF node.
No credentials required. The plugin bundles the ATR ruleset via the pyatr
package (requirements.txt). Provider validation smoke-tests that the engine
loads.
dify plugin package ./agent-threat-rules # produces agent-threat-rules-0.1.0.difypkg
Then PR the plugin directory + the .difypkg to langgenius/dify-plugins under
your marketplace org. See ../PR-DRAFT.md.
See PRIVACY.md. No data collection; local detection only. Risk level: Low.