Privacy Policy — Agent Threat Rules plugin
This plugin runs entirely on the host where Dify executes it. Text submitted to
the scan tool is evaluated locally against the bundled Agent Threat Rules
ruleset.
- No user data is collected, stored, or transmitted off-host by this plugin.
- No external network calls are made during scanning. Detection is local
pattern evaluation via the open-source
pyatrengine. - The plugin requests only the
toolpermission. It does not access models, storage, endpoints, or workflow nodes.
If you configure the plugin to load rules from a remote URL (not the default), that request is made by your deployment to the URL you specify; the default configuration uses the rules bundled with the package and makes no network call.