{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/openai-guardrails.json",
        "name": "OpenAI Guardrails",
        "score": 69.5,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy",
          "guard.self-host"
        ],
        "slug": "openai-guardrails"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/nemo-guardrails.json",
        "name": "NVIDIA NeMo Guardrails",
        "score": 68.4,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy",
          "guard.self-host"
        ],
        "slug": "nemo-guardrails"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/lakera-guard.json",
        "name": "Lakera Guard (Check Point AI Guardrails)",
        "score": 59.6,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy",
          "guard.self-host"
        ],
        "slug": "lakera-guard"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/guardrails-ai.json",
        "name": "Guardrails AI",
        "score": 49.6,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy",
          "guard.self-host"
        ],
        "slug": "guardrails-ai"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-model-armor.json",
        "name": "Google Cloud Model Armor",
        "score": 77.9,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy"
        ],
        "slug": "google-model-armor"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.json",
        "name": "Amazon Bedrock Guardrails",
        "score": 74.8,
        "shared": [
          "guard.injection",
          "guard.pii",
          "guard.policy"
        ],
        "slug": "amazon-bedrock-guardrails"
      }
    ],
    "tool": {
      "slug": "llamafirewall",
      "name": "LlamaFirewall",
      "vendor": "Meta",
      "vendorUrl": "https://dev.meta.ai/llama/llama-protections",
      "kind": "framework",
      "category": "guardrails",
      "summary": "LlamaFirewall is Meta's open-source Python library for screening an AI agent's inputs, tool results and outputs. It runs scanners for prompt injection, hidden characters, insecure generated code and goal drift, and returns allow, block or human review.",
      "url": "https://www.anchorterminal.com/tools/llamafirewall",
      "markdownUrl": "https://www.anchorterminal.com/tools/llamafirewall.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/llamafirewall.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/llamafirewall.json",
      "repo": "https://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall",
      "license": "MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence",
      "transports": [],
      "packages": [
        {
          "registry": "pypi",
          "name": "llamafirewall"
        }
      ],
      "auth": "none",
      "authNotes": "The library has no account or key of its own. The Prompt Guard scanner needs a Hugging Face token for an account Meta has approved for the gated `meta-llama/Llama-Prompt-Guard-2-86M` weights. AlignmentCheck and the PII scanner need `TOGETHER_API_KEY` for Together AI. The regex, hidden ASCII and CodeShield scanners need neither.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy from Meta and no hosted version found. The cost is the owner's compute, plus Together AI's own charges when AlignmentCheck or the PII scanner is switched on. Those were not priced here.",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. LlamaFirewall is a library the owner runs, with no payment route (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4423,
        "npmWeekly": null,
        "pypiWeekly": 1029,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://meta-llama.github.io/PurpleLlama/LlamaFirewall/",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "framework",
        "open-source",
        "self-hosted",
        "local",
        "python",
        "free",
        "gated",
        "no-telemetry",
        "stale-release"
      ],
      "lastRelease": "2025-05-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.8,
        "grade": "D",
        "agentReady": false,
        "rank": 682,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 13,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 15,
          "payments": 50,
          "reliability": 53,
          "schema": 49,
          "security": 56,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 53,
            "points": 10.6,
            "reason": "Scored on the local-software lines, since the owner runs the library. It installs from PyPI as `llamafirewall`, and the README states Python 3.10 or later, but the package metadata carries no Python requirement and every dependency has a lower bound only. The 1.0.3 wheel imports `HfFolder` from `huggingface_hub`, which 2.2.0 no longer exports, so by our reading of the source a fresh install cannot load the Prompt Guard scanner without older pins. We did not run it (10 of 20). A public tests workflow runs 35 LlamaFirewall unit tests on Python 3.10 and 3.12 and passed on main on 29 September 2026. The models are mocked, the lint job failed the same day, and CI tests main, not the released wheel (20 of 25). Issues 114, 116 and 117 from June and July 2025 and issue 219 from April 2026 have no reply, and pull request 185, which fixes the import error, has been open since 13 March 2026 (8 of 25). Version numbers follow semver in form, but there is no changelog, and no tags were present in our clone (3 of 15). Version 1.0.3, with two of six scanners under `scanners/experimental` (12 of 15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 49,
            "points": 7.96,
            "reason": "Framework reading. There is no API reference page and no specification. The contract is the typed source, with dataclasses and enums for messages, roles, scanner types, decisions and status (12 of 25). No llms.txt on the docs site (404). The docs are Markdown in the repository (5 of 10). Each scanner has a page that states its purpose and the risks it covers. None says when not to use it or what it misses (12 of 20). Roles, scanner types and decisions are enums. `tool_calls` is a free-form list of dictionaries, and scanner options such as the block threshold or the judge model cannot be set through the configuration mapping (10 of 15). Eleven example scripts, a notebook and five tutorials. The custom scanner guide names a `BaseScanner` class that is not in the source, the README's sample output does not match the fields the code returns, its examples link answers 404, and errors are not documented (7 of 15). PyPI version numbers only, with no changelog (3 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 60,
            "points": 9.75,
            "reason": "Read as a classifier an agent calls in process. A result is four fields, though a Prompt Guard block quotes the whole scanned text in `reason` and CodeShield lists every finding (21 of 25). Scanners are chosen per role and two preset use cases exist. Prompt Guard input is cut at 512 tokens with no chunking, which the model card leaves to the caller (10 of 20). A `status` field and a clear message for a missing key exist. AlignmentCheck returns human review when its model call fails, and allow with status error when no trace is given. `scan()` wraps `asyncio.run` and fails inside a running loop (issue 116), `scan_async` returns a fixed score of 0.0 on allow, and none of this is documented (8 of 20). Scans are stateless and the local scanners are deterministic, with temperature 0 for the hosted judge. Each scan builds a new scanner, which reloads the model from disk (14 of 20). Working defaults with no arguments, Python only, and an interactive login prompt when no Hugging Face token is present (7 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 56,
            "points": 9.8,
            "reason": "Read as software the owner runs. No credential of its own. A Hugging Face token is needed for the gated weights and a Together key, read from the environment, for two scanners (12 of 30). Scanners only read text and return a decision. `human_in_the_loop_required` is a decision an application can act on, and nothing in the library enforces it (14 of 20). Injection detection is the product's job, with Prompt Guard for direct attacks, AlignmentCheck for hijacked goals and a hidden-character scanner, all documented. The AlignmentCheck judge itself reads the untrusted trace (13 of 15). Python logging only, with the hosted judge's answer logged at info level. No audit log (5 of 15). SECURITY.md routes reports to Meta's bug bounty. PyPI lists no known vulnerabilities for the package. No security.txt, no published advisories, and Dependabot pull requests for the docs site from May and June 2026 are unmerged (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 50,
            "points": 6.25,
            "reason": "Self-hosted rule, with one departure. MIT-licensed, with nothing to buy from Meta (20). Free to run with no card (20). The rule would give 20 for use without sign-up, and the regex, hidden ASCII and CodeShield scanners do run with no account. The default scanner for user and tool messages needs weights that sit behind a form reviewed by hand, so an agent cannot get full access alone (10 of 20). No payment protocol (0). Together AI charges for the two scanners that call it."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 15,
            "points": 1.31,
            "reason": "The last PyPI release is 1.0.3 on 29 May 2025, more than 16 months before the check (0 of 30). No release in the last 90 days (0 of 20). LlamaFirewall issues from June and July 2025 have no reply, and outside pull requests from August and September 2025 are still open. Pull request 185 has four comments and is unmerged after nearly seven months. The folder had four commits since 10 July 2026, all type-check and lint housekeeping (6 of 25). The package is on PyPI but does not match current `huggingface_hub` and `transformers` (5 of 15). Tests pass on main, lint and the site deployment workflow failed on 29 September 2026, and dependencies carry lower bounds only (4 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 58,
            "points": 5.08,
            "note": "editorial 56, provenance 60",
            "reason": "The library is MIT. The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence, which is not an OSI licence, and the repository root carries a third licence file (26 of 30). Four scanners keep text on the owner's machine. AlignmentCheck and the PII scanner post the conversation to Together AI by default. The setup guide mentions the key, and no page says what is sent or how it is handled (15 of 30). No deprecation policy, changelog or dated notices found (0 of 20). No telemetry code found in the library source, and the docs make no statement either way (15 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Read as a classifier an agent calls in process. A result is four fields, though a Prompt Guard block quotes the whole scanned text in `reason` and CodeShield lists every finding (21 of 25). Scanners are chosen per role and two preset use cases exist. Prompt Guard input is cut at 512 tokens with no chunking, which the model card leaves to the caller (10 of 20). A `status` field and a clear message for a missing key exist. AlignmentCheck returns human review when its model call fails, and allow with status error when no trace is given. `scan()` wraps `asyncio.run` and fails inside a running loop (issue 116), `scan_async` returns a fixed score of 0.0 on allow, and none of this is documented (8 of 20). Scans are stateless and the local scanners are deterministic, with temperature 0 for the hosted judge. Each scan builds a new scanner, which reloads the model from disk (14 of 20). Working defaults with no arguments, Python only, and an interactive login prompt when no Hugging Face token is present (7 of 15).",
            "maintenance": "The last PyPI release is 1.0.3 on 29 May 2025, more than 16 months before the check (0 of 30). No release in the last 90 days (0 of 20). LlamaFirewall issues from June and July 2025 have no reply, and outside pull requests from August and September 2025 are still open. Pull request 185 has four comments and is unmerged after nearly seven months. The folder had four commits since 10 July 2026, all type-check and lint housekeeping (6 of 25). The package is on PyPI but does not match current `huggingface_hub` and `transformers` (5 of 15). Tests pass on main, lint and the site deployment workflow failed on 29 September 2026, and dependencies carry lower bounds only (4 of 10).",
            "payments": "Self-hosted rule, with one departure. MIT-licensed, with nothing to buy from Meta (20). Free to run with no card (20). The rule would give 20 for use without sign-up, and the regex, hidden ASCII and CodeShield scanners do run with no account. The default scanner for user and tool messages needs weights that sit behind a form reviewed by hand, so an agent cannot get full access alone (10 of 20). No payment protocol (0). Together AI charges for the two scanners that call it.",
            "reliability": "Scored on the local-software lines, since the owner runs the library. It installs from PyPI as `llamafirewall`, and the README states Python 3.10 or later, but the package metadata carries no Python requirement and every dependency has a lower bound only. The 1.0.3 wheel imports `HfFolder` from `huggingface_hub`, which 2.2.0 no longer exports, so by our reading of the source a fresh install cannot load the Prompt Guard scanner without older pins. We did not run it (10 of 20). A public tests workflow runs 35 LlamaFirewall unit tests on Python 3.10 and 3.12 and passed on main on 29 September 2026. The models are mocked, the lint job failed the same day, and CI tests main, not the released wheel (20 of 25). Issues 114, 116 and 117 from June and July 2025 and issue 219 from April 2026 have no reply, and pull request 185, which fixes the import error, has been open since 13 March 2026 (8 of 25). Version numbers follow semver in form, but there is no changelog, and no tags were present in our clone (3 of 15). Version 1.0.3, with two of six scanners under `scanners/experimental` (12 of 15).",
            "schema": "Framework reading. There is no API reference page and no specification. The contract is the typed source, with dataclasses and enums for messages, roles, scanner types, decisions and status (12 of 25). No llms.txt on the docs site (404). The docs are Markdown in the repository (5 of 10). Each scanner has a page that states its purpose and the risks it covers. None says when not to use it or what it misses (12 of 20). Roles, scanner types and decisions are enums. `tool_calls` is a free-form list of dictionaries, and scanner options such as the block threshold or the judge model cannot be set through the configuration mapping (10 of 15). Eleven example scripts, a notebook and five tutorials. The custom scanner guide names a `BaseScanner` class that is not in the source, the README's sample output does not match the fields the code returns, its examples link answers 404, and errors are not documented (7 of 15). PyPI version numbers only, with no changelog (3 of 15).",
            "security": "Read as software the owner runs. No credential of its own. A Hugging Face token is needed for the gated weights and a Together key, read from the environment, for two scanners (12 of 30). Scanners only read text and return a decision. `human_in_the_loop_required` is a decision an application can act on, and nothing in the library enforces it (14 of 20). Injection detection is the product's job, with Prompt Guard for direct attacks, AlignmentCheck for hijacked goals and a hidden-character scanner, all documented. The AlignmentCheck judge itself reads the untrusted trace (13 of 15). Python logging only, with the hosted judge's answer logged at info level. No audit log (5 of 15). SECURITY.md routes reports to Meta's bug bounty. PyPI lists no known vulnerabilities for the package. No security.txt, no published advisories, and Dependabot pull requests for the docs site from May and June 2026 are unmerged (12 of 20).",
            "transparency": "The library is MIT. The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence, which is not an OSI licence, and the repository root carries a third licence file (26 of 30). Four scanners keep text on the owner's machine. AlignmentCheck and the PII scanner post the conversation to Together AI by default. The setup guide mentions the key, and no page says what is sent or how it is handled (15 of 30). No deprecation policy, changelog or dated notices found (0 of 20). No telemetry code found in the library source, and the docs make no statement either way (15 of 20)."
          },
          "sources": [
            {
              "what": "LlamaFirewall README and source tree (clone of main at 172c107, 29 September 2026)",
              "url": "https://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall",
              "seen": "2026-10-08"
            },
            {
              "what": "core library, defaults and scan methods",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall.py",
              "seen": "2026-10-08"
            },
            {
              "what": "Prompt Guard loader, model name and 512-token truncation",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/promptguard_utils.py",
              "seen": "2026-10-08"
            },
            {
              "what": "hosted judge model, endpoint and key for AlignmentCheck and PII",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/custom_check_scanner.py",
              "seen": "2026-10-08"
            },
            {
              "what": "package metadata and dependencies",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/pyproject.toml",
              "seen": "2026-10-08"
            },
            {
              "what": "security policy",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/SECURITY.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MIT licence",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/LICENSE",
              "seen": "2026-10-08"
            },
            {
              "what": "tests workflow",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/.github/workflows/tests.yml",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI release history; the 1.0.3 wheel was downloaded and read",
              "url": "https://pypi.org/pypi/llamafirewall/json",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI download counts",
              "url": "https://pypistats.org/api/packages/llamafirewall/recent",
              "seen": "2026-10-08"
            },
            {
              "what": "current huggingface_hub version; its wheel was read for the missing export",
              "url": "https://pypi.org/pypi/huggingface_hub/json",
              "seen": "2026-10-08"
            },
            {
              "what": "current transformers version and its huggingface-hub requirement",
              "url": "https://pypi.org/pypi/transformers/json",
              "seen": "2026-10-08"
            },
            {
              "what": "repository stars and push date",
              "url": "https://api.github.com/repos/meta-llama/PurpleLlama",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues and pull requests",
              "url": "https://api.github.com/repos/meta-llama/PurpleLlama/issues?state=open\u0026per_page=100",
              "seen": "2026-10-08"
            },
            {
              "what": "CI runs on main",
              "url": "https://api.github.com/repos/meta-llama/PurpleLlama/actions/runs?branch=main\u0026per_page=12",
              "seen": "2026-10-08"
            },
            {
              "what": "pull request 185, import error and scan_async",
              "url": "https://github.com/meta-llama/PurpleLlama/pull/185",
              "seen": "2026-10-08"
            },
            {
              "what": "issue 116, scan() inside an event loop",
              "url": "https://github.com/meta-llama/PurpleLlama/issues/116",
              "seen": "2026-10-08"
            },
            {
              "what": "Prompt Guard 2 86M gating and downloads",
              "url": "https://huggingface.co/api/models/meta-llama/Llama-Prompt-Guard-2-86M",
              "seen": "2026-10-08"
            },
            {
              "what": "Prompt Guard 2 86M model card",
              "url": "https://github.com/meta-llama/PurpleLlama/blob/main/Llama-Prompt-Guard-2/86M/MODEL_CARD.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs site",
              "url": "https://meta-llama.github.io/PurpleLlama/LlamaFirewall/",
              "seen": "2026-10-08"
            },
            {
              "what": "Meta's Llama Protections page",
              "url": "https://dev.meta.ai/llama/llama-protections",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for llama.com",
              "url": "https://rdap.verisign.com/com/v1/domain/llama.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: we did not install or run the package. The import failure with current `huggingface_hub` is read from the 1.0.3 wheel, the `huggingface_hub` 2.2.0 wheel and pull request 185.",
            "unchecked: who wrote the four comments on pull request 185 and whether Meta staff replied. The GitHub API stopped answering after six requests and we did not retry.",
            "unchecked: whether the repository has version tags or GitHub releases for LlamaFirewall. None were in a clone of depth 200.",
            "unchecked: Together AI's prices and data terms for the two scanners that call it.",
            "unchecked: the LlamaFirewall paper's benchmark figures. The paper was not read.",
            "The lead named Prompt Guard, alignment checks and CodeShield from memory. All three are in the source, along with regex, hidden ASCII and an experimental PII scanner.",
            "No privacy document governs the library, so `provenance.privacy` is left out. `provenance.terms` is the MIT licence file."
          ]
        },
        "negative": 0,
        "verdict": "One `scan()` call runs several checks on the owner's machine and returns a short typed result. The last PyPI release is 1.0.3 from 29 May 2025, and its Prompt Guard loader imports a `huggingface_hub` class that current versions no longer export, so a fresh install needs older pins. The classifier weights also need Meta's manual approval.",
        "bestFor": "A Python agent team that wants injection, hidden-character and generated-code checks in process, is willing to pin dependencies or install from main, and can get the gated weights.",
        "strengths": [
          "Six scanner types sit behind one call, set per message role (user, assistant, tool, system, memory) in a plain mapping",
          "`ScanResult` is four typed fields (`decision`, `reason`, `score`, `status`), with decisions limited to allow, block or human review",
          "Prompt Guard, CodeShield, regex and hidden-character scanners run locally, and no telemetry code was found in the source",
          "MIT licence for the library, with tests run in public CI on Python 3.10 and 3.12 that passed on main on 29 September 2026",
          "`scan_replay` checks a whole conversation trace, and AlignmentCheck compares each agent step with the first user message"
        ],
        "weaknesses": [
          "No PyPI release since 1.0.3 on 29 May 2025, and no changelog, tags or deprecation notes were found",
          "The 1.0.3 wheel imports `HfFolder` from `huggingface_hub`, which version 2.2.0 no longer exports. Main fixed the scanner on 26 March 2026, unreleased",
          "The Prompt Guard 2 weights are gated on Hugging Face with manual review, and the loader calls an interactive `login()` when no token is set",
          "Prompt Guard input is truncated at 512 tokens in the library, so later text in a long tool result is not scored",
          "AlignmentCheck and the PII scanner send the conversation to Together AI by default, and `create_scanner` passes no option to change the model or endpoint",
          "The custom scanner guide names a `BaseScanner` class that is not in the source, and LlamaFirewall issues from June and July 2025 have no reply"
        ],
        "agentNotes": [
          "Pin `huggingface_hub` below 1.0 and a matching `transformers` 4.x before importing the Prompt Guard scanner from the 1.0.3 wheel, or install from main",
          "Get access to `meta-llama/Llama-Prompt-Guard-2-86M` and set a Hugging Face token first. Without one the loader prompts for a login and a headless run stalls",
          "Call `scan_async` inside a running event loop. `scan()` wraps `asyncio.run` and fails there. `scan_async` returns score 0.0 and reason `default` on every allow",
          "Split text longer than 512 tokens yourself before a Prompt Guard scan. The library truncates and does not chunk",
          "Do not feed a block `reason` back to the model. The Prompt Guard reason quotes the full scanned text, and the hidden ASCII reason decodes the hidden payload"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.8
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 15,
          "payments": 50,
          "reliability": 53,
          "schema": 49,
          "security": 56,
          "transparency": 56
        },
        "provenanceScore": 60
      },
      "connect": {
        "install": "pip install llamafirewall\nllamafirewall configure"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/llamafirewall"
      },
      "sameCompany": [
        "llama-guard"
      ],
      "notable": [
        "The package is `llamafirewall` on PyPI, version 1.0.3 uploaded 29 May 2025, with 13 uploads in total and the first on 23 April 2025 (https://pypi.org/pypi/llamafirewall/json)",
        "Scanner types in the source are `code_shield`, `prompt_guard`, `agent_alignment`, `hidden_ascii`, `pii_detection` and `regex`. AlignmentCheck and the PII scanner sit under `scanners/experimental` (https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall_data_types.py)",
        "With no configuration, tool messages get CodeShield and Prompt Guard, user messages Prompt Guard and assistant messages CodeShield (https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall.py)",
        "The Prompt Guard scanner loads `meta-llama/Llama-Prompt-Guard-2-86M`, blocks at a score of 0.9 and truncates input at 512 tokens (https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/promptguard_utils.py)",
        "That model is gated on Hugging Face with manual review and asks for name, date of birth, country, affiliation and job title. It showed 122,369 downloads in the last month (https://huggingface.co/api/models/meta-llama/Llama-Prompt-Guard-2-86M)",
        "AlignmentCheck calls `meta-llama/Llama-4-Maverick-17B-128E-Instruct-FP8` and the PII scanner `meta-llama/Llama-3.3-70B-Instruct-Turbo`, both at api.together.xyz with `TOGETHER_API_KEY` (https://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/custom_check_scanner.py)",
        "The 1.0.3 wheel imports `HfFolder` from `huggingface_hub` in `scanners/promptguard_utils.py` and `cli/configure.py`. `huggingface_hub` 2.2.0 does not export it, and `transformers` 5.19.0 needs `huggingface-hub` 1.31 or later (https://pypi.org/pypi/huggingface_hub/json, https://pypi.org/pypi/transformers/json)",
        "Pull request 185, opened 13 March 2026 and still open, reports the `HfFolder` import error and that `scan_async` discards scores on allow (https://github.com/meta-llama/PurpleLlama/pull/185)",
        "Meta's model card gives Prompt Guard 2 86M an AUC of 0.998 in English and 97.5 per cent recall at 1 per cent false positives, on Meta's own evaluation (https://github.com/meta-llama/PurpleLlama/blob/main/Llama-Prompt-Guard-2/86M/MODEL_CARD.md)",
        "PyPI downloads were 1,029 in the last week and 4,553 in the last month (https://pypistats.org/api/packages/llamafirewall/recent)"
      ],
      "area": "models",
      "details": [
        {
          "label": "Package",
          "value": "`llamafirewall` 1.0.3 on PyPI (29 May 2025). Depends on `codeshield`, `torch`, `transformers`, `huggingface_hub`, `openai`, `pydantic`, `typer` and `numpy`, each with a lower bound only"
        },
        {
          "label": "Languages",
          "value": "Python 3.10 or later per the README. The package metadata states no Python requirement"
        },
        {
          "label": "Scanners",
          "value": "Prompt Guard 2 (local classifier), CodeShield (static analysis of generated code), regex (five default patterns), hidden ASCII (Unicode tag characters), AlignmentCheck and PII check (both experimental, both calling a hosted model)"
        },
        {
          "label": "Calls",
          "value": "`scan`, `scan_async`, `scan_replay`, `scan_replay_async`, `scan_replay_build_trace` and `scan_replay_build_trace_async` on the `LlamaFirewall` class"
        },
        {
          "label": "Result",
          "value": "`ScanResult` with `decision` (allow, block, human_in_the_loop_required), `reason`, `score` from 0 to 1 and `status` (success, error, skipped)"
        },
        {
          "label": "Configuration",
          "value": "A mapping from role to a list of scanner types, or `LlamaFirewall.from_usecase` with `chatbot` or `coding_assistant`. Custom scanners register with `register_llamafirewall_scanner`"
        },
        {
          "label": "Models",
          "value": "`meta-llama/Llama-Prompt-Guard-2-86M`, gated on Hugging Face with manual review, under the Llama 4 Community Licence. Saved under `HF_HOME` after the first download"
        },
        {
          "label": "Outside calls",
          "value": "AlignmentCheck and the PII scanner post the trace to api.together.xyz through the `openai` client, with `TOGETHER_API_KEY`. The other four scanners make no network call after the model download"
        },
        {
          "label": "Command line",
          "value": "`llamafirewall configure` checks for the local model and the Together key, and can download the model"
        },
        {
          "label": "Integrations",
          "value": "Example scripts for the OpenAI Agents SDK guardrail hook and for LangChain with LangGraph"
        },
        {
          "label": "Telemetry",
          "value": "None found in the library source (searched 2026-10-08). The docs make no statement"
        },
        {
          "label": "Releases in 90 days",
          "value": "0. The last upload was 1.0.3 on 2025-05-29"
        },
        {
          "label": "Support",
          "value": "Issues at github.com/meta-llama/PurpleLlama. Security reports through Meta's bug bounty at bugbounty.meta.com"
        }
      ],
      "provenance": {
        "legalEntity": "Meta Platforms, Inc.",
        "domain": "llama.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "A Python library the owner runs, not a service. Code is on github.com under the meta-llama organisation, docs on meta-llama.github.io, and Meta's Llama Protections page lists it.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The MIT licence in the LlamaFirewall folder is the document that governs use of the library, so it is recorded as the terms. Its copyright line reads Meta Platforms, Inc. and affiliates.",
          "The Prompt Guard 2 weights the library downloads are under the Llama 4 Community Licence, a separate document, and the repository root carries a Llama 3.2 licence file.",
          "No privacy policy governs the library, because the owner runs it. The privacy field is left out. The Hugging Face access form for the weights says details entered are handled under the Meta Privacy Policy.",
          "AlignmentCheck and the PII scanner send data to Together AI under the owner's own Together account. Meta publishes no data statement for that path.",
          "www.llama.com/llama-protections redirected to dev.meta.ai/llama/llama-protections on 8 October 2026, which names LlamaFirewall and links its paper. RDAP gives 1 November 1994 as the registration date of llama.com.",
          "No status page, because nothing is hosted. No changelog, release notes or version tags were found in the repository.",
          "security.txt returns 404 on meta-llama.github.io and dev.meta.ai. SECURITY.md in the LlamaFirewall folder sends reports to bugbounty.meta.com."
        ],
        "score": 60,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Meta Platforms, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "llama.com, registered 1994-11-01 (31 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/llamafirewall.json"
    },
    "verify": {
      "accepts": "a page on llama.com or dev.meta.ai or one of their subdomains, or the README of github.com/meta-llama/PurpleLlama",
      "badgeUrl": "https://www.anchorterminal.com/badges/llamafirewall.svg",
      "body": {
        "slug": "llamafirewall",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/llamafirewall",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/llamafirewall\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/llamafirewall.svg\" alt=\"LlamaFirewall on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![LlamaFirewall on Anchor Terminal](https://www.anchorterminal.com/badges/llamafirewall.svg)](https://www.anchorterminal.com/tools/llamafirewall)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/llamafirewall\"\u003eLlamaFirewall on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/llamafirewall",
    "json": "https://www.anchorterminal.com/tools/llamafirewall.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/llamafirewall.md",
    "slim": "https://www.anchorterminal.com/tools/llamafirewall.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 50.8/100 · rank #682 of 842 · #13 in Guardrails \u0026 safety filters · not agent-ready · confidence medium**\n\n\nMore from Meta, listed separately because each is its own product: [Llama Guard 4](https://www.anchorterminal.com/tools/llama-guard.md) (Guardrails \u0026 safety filters).\n\n## Assessment\n\nOne `scan()` call runs several checks on the owner's machine and returns a short typed result. The last PyPI release is 1.0.3 from 29 May 2025, and its Prompt Guard loader imports a `huggingface_hub` class that current versions no longer export, so a fresh install needs older pins. The classifier weights also need Meta's manual approval.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Meta (https://dev.meta.ai/llama/llama-protections) |\n| Kind | Agent framework |\n| Category | Guardrails \u0026 safety filters (https://www.anchorterminal.com/categories/guardrails) |\n| Auth | None · The library has no account or key of its own. The Prompt Guard scanner needs a Hugging Face token for an account Meta has approved for the gated `meta-llama/Llama-Prompt-Guard-2-86M` weights. AlignmentCheck and the PII scanner need `TOGETHER_API_KEY` for Together AI. The regex, hidden ASCII and CodeShield scanners need neither. |\n| Pricing | Free (Free · OSS) · Free under the MIT licence, with nothing to buy from Meta and no hosted version found. The cost is the owner's compute, plus Together AI's own charges when AlignmentCheck or the PII scanner is switched on. Those were not priced here. |\n| x402 | No · No x402, MPP or L402 in the docs or the source. LlamaFirewall is a library the owner runs, with no payment route (checked 2026-10-08). |\n| Licence | MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence |\n| Packages | pypi: `llamafirewall` |\n| Source | https://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall |\n| Docs | https://meta-llama.github.io/PurpleLlama/LlamaFirewall/ |\n| llms.txt | not found |\n| Last release | 2025-05-29 |\n| GitHub stars | 4,423 (as of 2026-10-08) |\n| PyPI downloads / week | 1,029 |\n| Package | `llamafirewall` 1.0.3 on PyPI (29 May 2025). Depends on `codeshield`, `torch`, `transformers`, `huggingface_hub`, `openai`, `pydantic`, `typer` and `numpy`, each with a lower bound only |\n| Languages | Python 3.10 or later per the README. The package metadata states no Python requirement |\n| Scanners | Prompt Guard 2 (local classifier), CodeShield (static analysis of generated code), regex (five default patterns), hidden ASCII (Unicode tag characters), AlignmentCheck and PII check (both experimental, both calling a hosted model) |\n| Calls | `scan`, `scan_async`, `scan_replay`, `scan_replay_async`, `scan_replay_build_trace` and `scan_replay_build_trace_async` on the `LlamaFirewall` class |\n| Result | `ScanResult` with `decision` (allow, block, human_in_the_loop_required), `reason`, `score` from 0 to 1 and `status` (success, error, skipped) |\n| Configuration | A mapping from role to a list of scanner types, or `LlamaFirewall.from_usecase` with `chatbot` or `coding_assistant`. Custom scanners register with `register_llamafirewall_scanner` |\n| Models | `meta-llama/Llama-Prompt-Guard-2-86M`, gated on Hugging Face with manual review, under the Llama 4 Community Licence. Saved under `HF_HOME` after the first download |\n| Outside calls | AlignmentCheck and the PII scanner post the trace to api.together.xyz through the `openai` client, with `TOGETHER_API_KEY`. The other four scanners make no network call after the model download |\n| Command line | `llamafirewall configure` checks for the local model and the Together key, and can download the model |\n| Integrations | Example scripts for the OpenAI Agents SDK guardrail hook and for LangChain with LangGraph |\n| Telemetry | None found in the library source (searched 2026-10-08). The docs make no statement |\n| Releases in 90 days | 0. The last upload was 1.0.3 on 2025-05-29 |\n| Support | Issues at github.com/meta-llama/PurpleLlama. Security reports through Meta's bug bounty at bugbounty.meta.com |\n| Capabilities | guard.injection, guard.pii, guard.policy, guard.self-host |\n| Tags | framework, open-source, self-hosted, local, python, free, gated, no-telemetry, stale-release |\n| JSON | https://www.anchorterminal.com/api/v1/tools/llamafirewall.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 53 | 10.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 49 | 8.0 |\n| Agent ergonomics | 13% | 16.2 | 60 | 9.8 |\n| Security \u0026 auth | 14% | 17.5 | 56 | 9.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 50 | 6.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 15 | 1.3 |\n| Transparency \u0026 trust (editorial 56, provenance 60) | 7% | 8.8 | 58 | 5.1 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **50.8 → D** |\n\n### Why each score\n\n- Reliability 53: Scored on the local-software lines, since the owner runs the library. It installs from PyPI as `llamafirewall`, and the README states Python 3.10 or later, but the package metadata carries no Python requirement and every dependency has a lower bound only. The 1.0.3 wheel imports `HfFolder` from `huggingface_hub`, which 2.2.0 no longer exports, so by our reading of the source a fresh install cannot load the Prompt Guard scanner without older pins. We did not run it (10 of 20). A public tests workflow runs 35 LlamaFirewall unit tests on Python 3.10 and 3.12 and passed on main on 29 September 2026. The models are mocked, the lint job failed the same day, and CI tests main, not the released wheel (20 of 25). Issues 114, 116 and 117 from June and July 2025 and issue 219 from April 2026 have no reply, and pull request 185, which fixes the import error, has been open since 13 March 2026 (8 of 25). Version numbers follow semver in form, but there is no changelog, and no tags were present in our clone (3 of 15). Version 1.0.3, with two of six scanners under `scanners/experimental` (12 of 15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 49: Framework reading. There is no API reference page and no specification. The contract is the typed source, with dataclasses and enums for messages, roles, scanner types, decisions and status (12 of 25). No llms.txt on the docs site (404). The docs are Markdown in the repository (5 of 10). Each scanner has a page that states its purpose and the risks it covers. None says when not to use it or what it misses (12 of 20). Roles, scanner types and decisions are enums. `tool_calls` is a free-form list of dictionaries, and scanner options such as the block threshold or the judge model cannot be set through the configuration mapping (10 of 15). Eleven example scripts, a notebook and five tutorials. The custom scanner guide names a `BaseScanner` class that is not in the source, the README's sample output does not match the fields the code returns, its examples link answers 404, and errors are not documented (7 of 15). PyPI version numbers only, with no changelog (3 of 15).\n- Agent ergonomics 60: Read as a classifier an agent calls in process. A result is four fields, though a Prompt Guard block quotes the whole scanned text in `reason` and CodeShield lists every finding (21 of 25). Scanners are chosen per role and two preset use cases exist. Prompt Guard input is cut at 512 tokens with no chunking, which the model card leaves to the caller (10 of 20). A `status` field and a clear message for a missing key exist. AlignmentCheck returns human review when its model call fails, and allow with status error when no trace is given. `scan()` wraps `asyncio.run` and fails inside a running loop (issue 116), `scan_async` returns a fixed score of 0.0 on allow, and none of this is documented (8 of 20). Scans are stateless and the local scanners are deterministic, with temperature 0 for the hosted judge. Each scan builds a new scanner, which reloads the model from disk (14 of 20). Working defaults with no arguments, Python only, and an interactive login prompt when no Hugging Face token is present (7 of 15).\n- Security \u0026 auth 56: Read as software the owner runs. No credential of its own. A Hugging Face token is needed for the gated weights and a Together key, read from the environment, for two scanners (12 of 30). Scanners only read text and return a decision. `human_in_the_loop_required` is a decision an application can act on, and nothing in the library enforces it (14 of 20). Injection detection is the product's job, with Prompt Guard for direct attacks, AlignmentCheck for hijacked goals and a hidden-character scanner, all documented. The AlignmentCheck judge itself reads the untrusted trace (13 of 15). Python logging only, with the hosted judge's answer logged at info level. No audit log (5 of 15). SECURITY.md routes reports to Meta's bug bounty. PyPI lists no known vulnerabilities for the package. No security.txt, no published advisories, and Dependabot pull requests for the docs site from May and June 2026 are unmerged (12 of 20).\n- Payments \u0026 pricing 50: Self-hosted rule, with one departure. MIT-licensed, with nothing to buy from Meta (20). Free to run with no card (20). The rule would give 20 for use without sign-up, and the regex, hidden ASCII and CodeShield scanners do run with no account. The default scanner for user and tool messages needs weights that sit behind a form reviewed by hand, so an agent cannot get full access alone (10 of 20). No payment protocol (0). Together AI charges for the two scanners that call it.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 15: The last PyPI release is 1.0.3 on 29 May 2025, more than 16 months before the check (0 of 30). No release in the last 90 days (0 of 20). LlamaFirewall issues from June and July 2025 have no reply, and outside pull requests from August and September 2025 are still open. Pull request 185 has four comments and is unmerged after nearly seven months. The folder had four commits since 10 July 2026, all type-check and lint housekeeping (6 of 25). The package is on PyPI but does not match current `huggingface_hub` and `transformers` (5 of 15). Tests pass on main, lint and the site deployment workflow failed on 29 September 2026, and dependencies carry lower bounds only (4 of 10).\n- Transparency \u0026 trust 58: The library is MIT. The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence, which is not an OSI licence, and the repository root carries a third licence file (26 of 30). Four scanners keep text on the owner's machine. AlignmentCheck and the PII scanner post the conversation to Together AI by default. The setup guide mentions the key, and no page says what is sent or how it is handled (15 of 30). No deprecation policy, changelog or dated notices found (0 of 20). No telemetry code found in the library source, and the docs make no statement either way (15 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/llamafirewall.md (JSON https://www.anchorterminal.com/fixes/llamafirewall.json)\n\n### What we couldn't check\n\n- unchecked: we did not install or run the package. The import failure with current `huggingface_hub` is read from the 1.0.3 wheel, the `huggingface_hub` 2.2.0 wheel and pull request 185.\n- unchecked: who wrote the four comments on pull request 185 and whether Meta staff replied. The GitHub API stopped answering after six requests and we did not retry.\n- unchecked: whether the repository has version tags or GitHub releases for LlamaFirewall. None were in a clone of depth 200.\n- unchecked: Together AI's prices and data terms for the two scanners that call it.\n- unchecked: the LlamaFirewall paper's benchmark figures. The paper was not read.\n- The lead named Prompt Guard, alignment checks and CodeShield from memory. All three are in the source, along with regex, hidden ASCII and an experimental PII scanner.\n- No privacy document governs the library, so `provenance.privacy` is left out. `provenance.terms` is the MIT licence file.\n\n### Sources\n\n- LlamaFirewall README and source tree (clone of main at 172c107, 29 September 2026): \u003chttps://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall\u003e (seen 2026-10-08)\n- core library, defaults and scan methods: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall.py\u003e (seen 2026-10-08)\n- Prompt Guard loader, model name and 512-token truncation: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/promptguard_utils.py\u003e (seen 2026-10-08)\n- hosted judge model, endpoint and key for AlignmentCheck and PII: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/custom_check_scanner.py\u003e (seen 2026-10-08)\n- package metadata and dependencies: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/pyproject.toml\u003e (seen 2026-10-08)\n- security policy: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/SECURITY.md\u003e (seen 2026-10-08)\n- MIT licence: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/LICENSE\u003e (seen 2026-10-08)\n- tests workflow: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/.github/workflows/tests.yml\u003e (seen 2026-10-08)\n- PyPI release history; the 1.0.3 wheel was downloaded and read: \u003chttps://pypi.org/pypi/llamafirewall/json\u003e (seen 2026-10-08)\n- PyPI download counts: \u003chttps://pypistats.org/api/packages/llamafirewall/recent\u003e (seen 2026-10-08)\n- current huggingface_hub version; its wheel was read for the missing export: \u003chttps://pypi.org/pypi/huggingface_hub/json\u003e (seen 2026-10-08)\n- current transformers version and its huggingface-hub requirement: \u003chttps://pypi.org/pypi/transformers/json\u003e (seen 2026-10-08)\n- repository stars and push date: \u003chttps://api.github.com/repos/meta-llama/PurpleLlama\u003e (seen 2026-10-08)\n- open issues and pull requests: \u003chttps://api.github.com/repos/meta-llama/PurpleLlama/issues?state=open\u0026per_page=100\u003e (seen 2026-10-08)\n- CI runs on main: \u003chttps://api.github.com/repos/meta-llama/PurpleLlama/actions/runs?branch=main\u0026per_page=12\u003e (seen 2026-10-08)\n- pull request 185, import error and scan_async: \u003chttps://github.com/meta-llama/PurpleLlama/pull/185\u003e (seen 2026-10-08)\n- issue 116, scan() inside an event loop: \u003chttps://github.com/meta-llama/PurpleLlama/issues/116\u003e (seen 2026-10-08)\n- Prompt Guard 2 86M gating and downloads: \u003chttps://huggingface.co/api/models/meta-llama/Llama-Prompt-Guard-2-86M\u003e (seen 2026-10-08)\n- Prompt Guard 2 86M model card: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/Llama-Prompt-Guard-2/86M/MODEL_CARD.md\u003e (seen 2026-10-08)\n- docs site: \u003chttps://meta-llama.github.io/PurpleLlama/LlamaFirewall/\u003e (seen 2026-10-08)\n- Meta's Llama Protections page: \u003chttps://dev.meta.ai/llama/llama-protections\u003e (seen 2026-10-08)\n- RDAP record for llama.com: \u003chttps://rdap.verisign.com/com/v1/domain/llama.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 60/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Meta Platforms, Inc. | 20/20 |\n| Domain age | llama.com, registered 1994-11-01 (31 years) | 15/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nA Python library the owner runs, not a service. Code is on github.com under the meta-llama organisation, docs on meta-llama.github.io, and Meta's Llama Protections page lists it.\n\nThe MIT licence in the LlamaFirewall folder is the document that governs use of the library, so it is recorded as the terms. Its copyright line reads Meta Platforms, Inc. and affiliates.\n\nThe Prompt Guard 2 weights the library downloads are under the Llama 4 Community Licence, a separate document, and the repository root carries a Llama 3.2 licence file.\n\nNo privacy policy governs the library, because the owner runs it. The privacy field is left out. The Hugging Face access form for the weights says details entered are handled under the Meta Privacy Policy.\n\nAlignmentCheck and the PII scanner send data to Together AI under the owner's own Together account. Meta publishes no data statement for that path.\n\nwww.llama.com/llama-protections redirected to dev.meta.ai/llama/llama-protections on 8 October 2026, which names LlamaFirewall and links its paper. RDAP gives 1 November 1994 as the registration date of llama.com.\n\nNo status page, because nothing is hosted. No changelog, release notes or version tags were found in the repository.\n\nsecurity.txt returns 404 on meta-llama.github.io and dev.meta.ai. SECURITY.md in the LlamaFirewall folder sends reports to bugbounty.meta.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Six scanner types sit behind one call, set per message role (user, assistant, tool, system, memory) in a plain mapping\n- `ScanResult` is four typed fields (`decision`, `reason`, `score`, `status`), with decisions limited to allow, block or human review\n- Prompt Guard, CodeShield, regex and hidden-character scanners run locally, and no telemetry code was found in the source\n- MIT licence for the library, with tests run in public CI on Python 3.10 and 3.12 that passed on main on 29 September 2026\n- `scan_replay` checks a whole conversation trace, and AlignmentCheck compares each agent step with the first user message\n\n## Weaknesses\n\n- No PyPI release since 1.0.3 on 29 May 2025, and no changelog, tags or deprecation notes were found\n- The 1.0.3 wheel imports `HfFolder` from `huggingface_hub`, which version 2.2.0 no longer exports. Main fixed the scanner on 26 March 2026, unreleased\n- The Prompt Guard 2 weights are gated on Hugging Face with manual review, and the loader calls an interactive `login()` when no token is set\n- Prompt Guard input is truncated at 512 tokens in the library, so later text in a long tool result is not scored\n- AlignmentCheck and the PII scanner send the conversation to Together AI by default, and `create_scanner` passes no option to change the model or endpoint\n- The custom scanner guide names a `BaseScanner` class that is not in the source, and LlamaFirewall issues from June and July 2025 have no reply\n\n## Before you call it (notes for agents)\n\n1. Pin `huggingface_hub` below 1.0 and a matching `transformers` 4.x before importing the Prompt Guard scanner from the 1.0.3 wheel, or install from main\n2. Get access to `meta-llama/Llama-Prompt-Guard-2-86M` and set a Hugging Face token first. Without one the loader prompts for a login and a headless run stalls\n3. Call `scan_async` inside a running event loop. `scan()` wraps `asyncio.run` and fails there. `scan_async` returns score 0.0 and reason `default` on every allow\n4. Split text longer than 512 tokens yourself before a Prompt Guard scan. The library truncates and does not chunk\n5. Do not feed a block `reason` back to the model. The Prompt Guard reason quotes the full scanned text, and the hidden ASCII reason decodes the hidden payload\n\n## Get started\n\nInstall:\n\n```bash\npip install llamafirewall\nllamafirewall configure\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| OpenAI Guardrails | B | 69.5 | 175 | guard.injection, guard.pii, guard.policy, guard.self-host | no | https://www.anchorterminal.com/tools/openai-guardrails.md |\n| NVIDIA NeMo Guardrails | B | 68.4 | 202 | guard.injection, guard.pii, guard.policy, guard.self-host | no | https://www.anchorterminal.com/tools/nemo-guardrails.md |\n| Lakera Guard (Check Point AI Guardrails) | C | 59.6 | 492 | guard.injection, guard.pii, guard.policy, guard.self-host | no | https://www.anchorterminal.com/tools/lakera-guard.md |\n| Guardrails AI | D | 49.6 | 701 | guard.injection, guard.pii, guard.policy, guard.self-host | no | https://www.anchorterminal.com/tools/guardrails-ai.md |\n| Google Cloud Model Armor | BB | 77.9 | 16 | guard.injection, guard.pii, guard.policy | no | https://www.anchorterminal.com/tools/google-model-armor.md |\n| Amazon Bedrock Guardrails | BB | 74.8 | 62 | guard.injection, guard.pii, guard.policy | no | https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The package is `llamafirewall` on PyPI, version 1.0.3 uploaded 29 May 2025, with 13 uploads in total and the first on 23 April 2025 (source: \u003chttps://pypi.org/pypi/llamafirewall/json\u003e)\n- Scanner types in the source are `code_shield`, `prompt_guard`, `agent_alignment`, `hidden_ascii`, `pii_detection` and `regex`. AlignmentCheck and the PII scanner sit under `scanners/experimental` (source: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall_data_types.py\u003e)\n- With no configuration, tool messages get CodeShield and Prompt Guard, user messages Prompt Guard and assistant messages CodeShield (source: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/llamafirewall.py\u003e)\n- The Prompt Guard scanner loads `meta-llama/Llama-Prompt-Guard-2-86M`, blocks at a score of 0.9 and truncates input at 512 tokens (source: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/promptguard_utils.py\u003e)\n- That model is gated on Hugging Face with manual review and asks for name, date of birth, country, affiliation and job title. It showed 122,369 downloads in the last month (source: \u003chttps://huggingface.co/api/models/meta-llama/Llama-Prompt-Guard-2-86M\u003e)\n- AlignmentCheck calls `meta-llama/Llama-4-Maverick-17B-128E-Instruct-FP8` and the PII scanner `meta-llama/Llama-3.3-70B-Instruct-Turbo`, both at api.together.xyz with `TOGETHER_API_KEY` (source: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/LlamaFirewall/src/llamafirewall/scanners/custom_check_scanner.py\u003e)\n- The 1.0.3 wheel imports `HfFolder` from `huggingface_hub` in `scanners/promptguard_utils.py` and `cli/configure.py`. `huggingface_hub` 2.2.0 does not export it, and `transformers` 5.19.0 needs `huggingface-hub` 1.31 or later (source: \u003chttps://pypi.org/pypi/huggingface_hub/json, https://pypi.org/pypi/transformers/json\u003e)\n- Pull request 185, opened 13 March 2026 and still open, reports the `HfFolder` import error and that `scan_async` discards scores on allow (source: \u003chttps://github.com/meta-llama/PurpleLlama/pull/185\u003e)\n- Meta's model card gives Prompt Guard 2 86M an AUC of 0.998 in English and 97.5 per cent recall at 1 per cent false positives, on Meta's own evaluation (source: \u003chttps://github.com/meta-llama/PurpleLlama/blob/main/Llama-Prompt-Guard-2/86M/MODEL_CARD.md\u003e)\n- PyPI downloads were 1,029 in the last week and 4,553 in the last month (source: \u003chttps://pypistats.org/api/packages/llamafirewall/recent\u003e)\n\n## Compare\n\n- [Amazon Bedrock Guardrails vs LlamaFirewall](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-llamafirewall.md): BB 74.8 vs D 50.8\n- [Azure AI Content Safety (Prompt Shields) vs LlamaFirewall](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-llamafirewall.md): C 60.7 vs D 50.8\n- [Cisco AI Defense Inspection API vs LlamaFirewall](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llamafirewall.md): C 61.3 vs D 50.8\n- [Google Cloud Model Armor vs LlamaFirewall](https://www.anchorterminal.com/compare/google-model-armor-vs-llamafirewall.md): BB 77.9 vs D 50.8\n- [Granite Guardian vs LlamaFirewall](https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall.md): C 60.1 vs D 50.8\n- [Guardrails AI vs LlamaFirewall](https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall.md): D 49.6 vs D 50.8\n- [Lakera Guard (Check Point AI Guardrails) vs LlamaFirewall](https://www.anchorterminal.com/compare/lakera-guard-vs-llamafirewall.md): C 59.6 vs D 50.8\n- [LlamaFirewall vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/llamafirewall-vs-nemo-guardrails.md): D 50.8 vs B 68.4\n- [LlamaFirewall vs OpenAI Guardrails](https://www.anchorterminal.com/compare/llamafirewall-vs-openai-guardrails.md): D 50.8 vs B 69.5\n- [LlamaFirewall vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/llamafirewall-vs-prisma-airs.md): D 50.8 vs B 62.8\n- [LlamaFirewall vs Presidio](https://www.anchorterminal.com/compare/llamafirewall-vs-microsoft-presidio.md): D 50.8 vs B 66\n- [LlamaFirewall vs Mistral Moderation API](https://www.anchorterminal.com/compare/llamafirewall-vs-mistral-moderation.md): D 50.8 vs C 58.4\n- [Llama Guard 4 vs LlamaFirewall](https://www.anchorterminal.com/compare/llama-guard-vs-llamafirewall.md): D 49.1 vs D 50.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on llama.com or dev.meta.ai or one of their subdomains, or the README of github.com/meta-llama/PurpleLlama. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"llamafirewall\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/llamafirewall\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/llamafirewall.svg\" alt=\"LlamaFirewall on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![LlamaFirewall on Anchor Terminal](https://www.anchorterminal.com/badges/llamafirewall.svg)](https://www.anchorterminal.com/tools/llamafirewall)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/llamafirewall\"\u003eLlamaFirewall on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say LlamaFirewall is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/llamafirewall-dark.png\n- Light: https://www.anchorterminal.com/assets/share/llamafirewall-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Guardrails \u0026 safety filters",
        "url": "https://www.anchorterminal.com/categories/guardrails"
      },
      {
        "name": "LlamaFirewall",
        "url": ""
      }
    ],
    "description": "LlamaFirewall is Meta's open-source Python library for screening an AI agent's inputs, tool results and outputs. It runs scanners for prompt injection, hidden characters, insecure generated code and goal drift, and returns allow, block or human review.",
    "facts": [
      "rank #682 of 842",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "LlamaFirewall",
    "image": "https://www.anchorterminal.com/assets/og/tools-llamafirewall.png",
    "path": "/tools/llamafirewall",
    "published": "2026-10-01",
    "section": "tools",
    "title": "LlamaFirewall review for AI agents, grade D (50.8/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/llamafirewall"
  },
  "tokens": {
    "markdown": 7350,
    "slim": 1630
  },
  "version": 1
}
