Skip to main content
Favicon of LLM Guard

LLM Guard

What is LLM Guard?

LLM Guard is an open-source security library for LLM applications: it runs a pipeline of scanners over prompts before they reach a model and over outputs before they reach a user, covering prompt injection, PII anonymization and deanonymization, secrets, toxicity and banned topics. It runs on CPU, is model-agnostic, and is documented for OpenAI, LiteLLM Proxy, LangChain and LlamaIndex, as a library or a self-hosted API server. The repository was archived in July 2026, so what exists today is a complete but frozen MIT-licensed codebase rather than a project in development.

Last verifiedHow we evaluate

Screenshot of LLM Guard website

At a glance

Best for
LLM Guard is best for AI teams who need lightweight security checks around prompts and outputs.

Archived on 8 July 2026 — no longer maintained

GitHub confirms protectai/llm-guard carries "archived": true, and the repository README displays a warning banner: "THIS PROJECT HAS BEEN ARCHIVED. This project and its associated models on Hugging Face are no longer under active development or maintained." The archiving commit (PR #355, merged 2026-07-08T23:58:40Z) simply added that banner — it gives no stated reason. Real feature and fix PRs had already slowed well before that: GitHub's search shows 18 merged PRs in 2025 against zero in the seven months before archival, and the last PyPI release, 0.3.16, shipped 19 May 2025 — over a year before the repository was closed. Five external PRs open at archival time, including two new scanner contributions submitted the same week, were never merged and remain open. One of those open, unmerged PRs (#353) would have unpinned a presidio-anonymizer version that transitively caps cryptography below the version fixing CVE-2026-26007 — a live dependency issue with no path to landing now. The code (MIT license) still installs via pip install llm-guard and runs; what stops is security patches, new scanners, and support for newer model/library versions going forward.

What it did well while it was maintained

LLM Guard's value was breadth in one package: input scanners (PromptInjection, Anonymize/PII detection via Microsoft Presidio, Secrets via detect-secrets, BanTopics, Toxicity, TokenLimit) and a parallel set of output scanners (Deanonymize, FactualConsistency, MaliciousURLs, NoRefusal, Bias), all usable independently or chained, framework-agnostic (LangChain and LiteLLM integrations existed but weren't required). At its peak it had real adoption signal for an open-source security library in this space — 3,208 GitHub stars and 462 forks as of 2026-09-24 — and a Hugging Face Space playground (44 likes) let you try scanners without installing anything.

Why it stopped: folded into Palo Alto Networks' Prisma AIRS

Palo Alto Networks announced it had completed its acquisition of Protect AI on 22 July 2025 (press release, PRNewswire). Protect AI's own domain, protectai.com, now redirects to paloaltonetworks.com/ai-security/prisma-airs — Protect AI's technology and team were folded into Palo Alto Networks' commercial Prisma AIRS platform rather than continued as a standalone open-source project. The archival came roughly a year after the acquisition closed, not immediately after it, and Protect AI's other open-source project, modelscan, remains unarchived with commits as recent as February 2026 — so this wasn't a blanket wind-down of everything Protect AI open-sourced, specifically llm-guard.

What using it today means

The MIT license permits forking, modifying, and running the code indefinitely with no legal obstacle. In practice: no security patches (the open, unmerged cryptography-CVE fix above is the concrete example), no new scanners, and dependency pins (Transformers 4.51.3, Presidio 2.2.358, Torch ≥2.4.0) that will age and eventually conflict with newer libraries in your environment. There is no official successor project from Protect AI/Palo Alto Networks pointing users to a maintained alternative — Prisma AIRS is a commercial platform, not a drop-in open-source replacement for this library.

Frequently asked questions

What is LLM Guard?

LLM Guard is an MIT-licensed Python library that filters LLM prompts and model outputs, with scanners for prompt injection, PII, secrets, toxicity, banned topics and malicious URLs. It can also be run as a self-hosted API server. Its repository has been read-only since 9 July 2026 and its last release, 0.3.16, dates from May 2025, so the code still works but receives no further fixes or model updates. Its prompt-injection model on Hugging Face logged about 838,000 downloads in the month to 2026-09-11.

What is LLM Guard used for? Who is it for?

It is used to put a filtering layer on both sides of a model call: blocking prompt-injection and jailbreak attempts, masking or stripping PII and secrets, scoring toxicity and sentiment, and keeping conversations off banned topics. It was built for AI/ML developers, security engineers and platform teams who want that layer self-hosted rather than bought as a service. Now that the project is archived, it fits teams willing to own and patch the code themselves.

Does LLM Guard have an API and what does it integrate with?

It ships an API you host yourself: the docs cover deploying the library as a FastAPI and Uvicorn service, with a reference and a client. There is no public API operated by the project, so there is no endpoint to call remotely and no key to obtain. It is model-agnostic: the docs cover calling OpenAI directly, putting it behind LiteLLM Proxy to moderate calls across providers such as Anthropic, Bedrock and Gemini, and wiring it into LangChain or LlamaIndex retrieval pipelines.

Editor's read

Still a reasonable fit if you want a self-hosted, MIT-licensed filter in front of your own model calls and can accept owning the code from here: the archived snapshot runs, but every future bug fix, model refresh and dependency bump is yours to make.

Share:

Sponsored
Favicon

 

  
 

Explore other Agent Tools & Integrations

Favicon

 

  
  
Favicon

 

  
  
Favicon