Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,6 @@ jobs:

- name: Validate package contents
run: npm pack --dry-run

- name: Verify isolated AI SDK consumers and registry example
run: bun run test:package
8 changes: 5 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,11 @@
# Changelog

## [Unreleased]
## [2.1.0] - 2026-10-04

- AI SDK 7 support, tested. `shieldLanguageModelMiddleware` works unchanged with AI SDK 7 (`ai@7`, `v4` language models) in `generateText` and `streamText`, and the test suite now runs it against AI SDK 4, 5, 6, and 7, including streaming, tool results, tool call arguments, `throwOnLeak`, and redaction.
- The legacy `shieldMiddleware().wrapParams()` and `wrapParamsAsync()` now also harden AI SDK 7's `instructions` option, which replaces the deprecated `system`. Before, a system prompt passed as `instructions` reached the model unhardened.
- Added `shieldCheck` at `@zeroleaks/shield/ai-sdk/tools` for AI SDK 5, 6, and 7. It uses local detection by default, supports explicit hosted detection and async local detectors, and returns detection metadata without repeating input text or matching patterns.
- Tool inputs are validated at the schema and execution boundaries. Oversized local input and incomplete hosted coverage reject rather than returning a verdict. Hosted failures and cancellation propagate as errors.
- Added isolated consumer checks for AI SDK 5–7, both module formats, and root imports without provider SDKs installed. The tool's runtime AI SDK dependency remains confined to its subpath.
- Confirmed middleware support for AI SDK 7, including `instructions` in the manual helper, generation, streaming, output guards, and raw response handling.

## [2.0.0] - 2026-10-02

Expand Down
23 changes: 23 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,29 @@ const result = await generateText({ model, prompt: userInput });

Pass `detect: shield.options()` to the other wrappers in the same way. Omitting it preserves the wrappers' existing local detection behavior. The AI SDK middleware waits for detection before the model call. The legacy `shieldMiddleware()` helper provides `await wrapParamsAsync(params)` for hosted detection; its synchronous `wrapParams()` accepts only local synchronous checks.

## AI SDK inspection tool

Shield 2.1.0 adds an inspection tool for AI SDK 5, 6, and 7:

```typescript
import { shieldCheck } from "@zeroleaks/shield/ai-sdk/tools";

const check = shieldCheck(); // Local; no network or API key.
const result = await check.execute(
{ text: "The document's complete original text.", source: "document" },
{}
);
if (result.detected) {
throw new Error("The document was blocked.");
}
```

Use `tools: { shieldCheck: shieldCheck() }` with `generateText` or `streamText` for model-invoked inspection. Pair it with `shieldLanguageModelMiddleware` for enforced checks before model calls: the model chooses whether to call the tool and which text to submit. A negative detection is not a guarantee of safety or permission to act. Tool execution errors become AI SDK `tool-error` parts; application code must decide whether the agent can continue.

Configure local checks with `shieldCheck({ detect: { sensitivity: "strict" } })`, or opt into hosted checks with `shieldCheck({ hosted: { apiKey, model: "shield" } })`. Hosted checks always require complete coverage and throw on missing or truncated coverage. Local checks reject oversized input instead of silently truncating it. The executor accepts `{ abortSignal }` as its second argument.

The new subpath requires `ai` 5 or later; AI SDK 7 requires Node.js 22+. Install `ai` and its `zod` peer alongside Shield. Other entry points still work without `ai` installed, and middleware retains SDK 4 support. See the [complete AI SDK tool guide](https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools) for a runnable model example, result fields, access requirements, and limitations.

## Request options

| Option | Default | Purpose |
Expand Down
10 changes: 8 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@zeroleaks/shield",
"version": "2.0.0",
"version": "2.1.0",
"description": "Runtime security for LLM apps and agents: prompt injection detection for user input and tool results, and leak, credential, PII, and exfiltration checks on model output",
"main": "dist/index.js",
"module": "dist/index.mjs",
Expand All @@ -26,6 +26,11 @@
"import": "./dist/providers/ai-sdk.mjs",
"require": "./dist/providers/ai-sdk.js"
},
"./ai-sdk/tools": {
"types": "./dist/providers/ai-sdk-tools.d.ts",
"import": "./dist/providers/ai-sdk-tools.mjs",
"require": "./dist/providers/ai-sdk-tools.js"
},
"./groq": {
"types": "./dist/providers/groq.d.ts",
"import": "./dist/providers/groq.mjs",
Expand Down Expand Up @@ -81,8 +86,9 @@
"dev": "tsup --watch",
"test": "bunx vitest run",
"test:watch": "bunx vitest",
"test:package": "bun scripts/verify-package.ts",
"typecheck": "tsc --noEmit -p .",
"prepublishOnly": "bun run typecheck && bun run test && bun run build",
"prepublishOnly": "bun run typecheck && bun run test && bun run build && bun run test:package",
"test:integration": "bunx vitest run --config vitest.integration.config.ts",
"benchmark": "bun run scripts/benchmark.ts",
"serve": "bun run src/server/cli.ts"
Expand Down
23 changes: 23 additions & 0 deletions registry/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# AI SDK registry submission

`entry.ts` contains the proposed object for `vercel/ai`'s `content/tools-registry/registry.ts`. `issue.md` is a ready-to-submit documentation-addition request. Neither file submits anything upstream.

The public integration guide is `https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools`. Its main example must match `entry.ts` exactly. The ZeroLeaks app's package verifier checks that parity; Shield's isolated package verifier type-checks and executes the registry snippet.

Before submitting, confirm that npm serves `@zeroleaks/shield@2.1.0` and the integration guide is live. The source repository, README, public docs, and published package must describe the same exports and supported SDK versions.

Run the release checks from the Shield repository:

```bash
bun install --frozen-lockfile
bun run typecheck
bun run test
bun run build
bun run test:package
```

The package verifier uses isolated npm installations and mocked model/API responses. It requires network access to npm, Node.js 22 or later, and no live model or Shield credentials. It does not send probe text to an external inference service.

The published entry should keep local detection as the default example and link directly to the AI SDK tool guide. An optional ZeroLeaks API key is documented on that page; it is not a prerequisite for the local tool. The model example requires `AI_GATEWAY_API_KEY`.

Follow the current [contribution guide](https://github.com/vercel/ai/blob/main/contributing/add-new-tool-to-registry.md). An issue-first documentation request has recent precedent, but may cause their automation to open a PR. Hold both the issue and PR until submission is authorized.
36 changes: 36 additions & 0 deletions registry/entry.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
export const shieldRegistryEntry = {
slug: "zeroleaks-shield",
name: "ZeroLeaks Shield",
description:
"Prompt injection and jailbreak detection for user messages, retrieved documents, web pages, and tool results. Inspect text with shieldCheck locally without an API key, or opt into the hosted Shield API. Pair it with Shield language model middleware to block detected injections before model calls.",
packageName: "@zeroleaks/shield",
tags: ["security", "guardrails", "prompt-injection", "jailbreak"],
installCommand: {
pnpm: "pnpm add @zeroleaks/shield ai zod",
npm: "npm install @zeroleaks/shield ai zod",
yarn: "yarn add @zeroleaks/shield ai zod",
bun: "bun add @zeroleaks/shield ai zod",
},
codeExample: `import { gateway, generateText, isStepCount, wrapLanguageModel } from 'ai';
import { shieldLanguageModelMiddleware } from '@zeroleaks/shield/ai-sdk';
import { shieldCheck } from '@zeroleaks/shield/ai-sdk/tools';

const model = wrapLanguageModel({
model: gateway('openai/gpt-5-mini'),
middleware: shieldLanguageModelMiddleware(),
});

const { text } = await generateText({
model,
tools: { shieldCheck: shieldCheck() },
stopWhen: isStepCount(3),
prompt:
'Check this support note with shieldCheck, then summarize it: Our support desk opens at nine on Monday.',
});

console.info(text);`,
docsUrl: "https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools",
apiKeyUrl: "https://zeroleaks.ai/dashboard/shield",
websiteUrl: "https://zeroleaks.ai/shield",
npmUrl: "https://www.npmjs.com/package/@zeroleaks/shield",
};
29 changes: 29 additions & 0 deletions registry/issue.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
### Description

I maintain `@zeroleaks/shield` and would like to add ZeroLeaks Shield to the AI SDK Tools Registry.

Shield provides `shieldCheck()` at `@zeroleaks/shield/ai-sdk/tools` for prompt injection and jailbreak detection in text agents read. It runs locally without a ZeroLeaks key or network request, or uses the hosted Shield API on explicit opt-in. The tool supports AI SDK 5, 6, and 7.

The package also provides `shieldLanguageModelMiddleware` to check user messages and tool results before model calls. The registry example combines both: model-invoked inspection is advisory, while middleware blocks detected injections before forwarding context. Neither a negative detector result nor a failed tool check authorizes an action.

- npm: https://www.npmjs.com/package/@zeroleaks/shield
- Canonical repository: https://github.com/ZeroLeaks/shield
- AI SDK integration guide: https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools
- Website: https://zeroleaks.ai/shield
- Version prepared and tested: `@zeroleaks/shield@2.1.0`
- Current SDK tested: `ai@7.0.127`
- Additional supported SDKs tested: `ai@5.0.267`, `ai@6.0.292`

The proposed entry is in `registry/entry.ts` in the Shield repository. Its complete code example appears verbatim in the integration guide. It uses `generateText`, `isStepCount`, and the AI Gateway provider with Shield middleware and `shieldCheck`.

### Validation

The release checks install the packed package in isolated consumer projects and verify `generateText`, `streamText`, malformed tool input, hosted failures, and middleware blocking on all three supported SDK versions. Both ESM and CommonJS consumer types are checked. The exact registry example is type-checked on SDK 7 and executed against a mocked Gateway for a two-step tool roundtrip. Root and middleware imports are also verified without the AI SDK or other provider peers installed.

Hosted checks require complete input coverage and throw on authentication failures, rate limits, timeouts, cancellation, invalid responses, or incomplete coverage. Local checks reject oversized input instead of returning a verdict for truncated text. Tool results omit input text and matching patterns.

The default registry example uses local detection. Hosted `shield` requires a dashboard key and research acknowledgement; paid models are available separately. The integration guide documents access, retention, coverage, and enforcement limitations.

### AI SDK version

7.0.127
Loading
Loading