# LlamaFirewall (slim) > LlamaFirewall is Meta's open-source Python library for screening an AI agent's inputs, tool results and outputs. It runs scanners for prompt injection, hidden characters, insecure generated code and goal drift, and returns allow, block or human review. - Full: https://www.anchorterminal.com/tools/llamafirewall.md (~7,350 tokens) · this version ~1,630 tokens · JSON https://www.anchorterminal.com/tools/llamafirewall.json · canonical https://www.anchorterminal.com/tools/llamafirewall - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **D · 50.8/100 · rank #682 of 842 · #13 in Guardrails & safety filters · not agent-ready · confidence medium** Assessment: One `scan()` call runs several checks on the owner's machine and returns a short typed result. The last PyPI release is 1.0.3 from 29 May 2025, and its Prompt Guard loader imports a `huggingface_hub` class that current versions no longer export, so a fresh install needs older pins. The classifier weights also need Meta's manual approval. ## Facts - Kind: Agent framework · vendor: Meta · category: Guardrails & safety filters · legal entity: Meta Platforms, Inc. · provenance 60/100 - Packages: pypi `llamafirewall` - Auth: None · pricing: Free · x402: no · licence: MIT (library). The Prompt Guard 2 weights it downloads are under the Llama 4 Community Licence - Probe metrics: not measured yet (probes haven't run) - Package: `llamafirewall` 1.0.3 on PyPI (29 May 2025). Depends on `codeshield`, `torch`, `transformers`, `huggingface_hub`, `openai`, `pydantic`, `typer` and `numpy`, each with a lower bound only - Languages: Python 3.10 or later per the README. The package metadata states no Python requirement - Scanners: Prompt Guard 2 (local classifier), CodeShield (static analysis of generated code), regex (five default patterns), hidden ASCII (Unicode tag characters), AlignmentCheck and PII check (both experimental, both calling a hosted model) - Calls: `scan`, `scan_async`, `scan_replay`, `scan_replay_async`, `scan_replay_build_trace` and `scan_replay_build_trace_async` on the `LlamaFirewall` class - Result: `ScanResult` with `decision` (allow, block, human_in_the_loop_required), `reason`, `score` from 0 to 1 and `status` (success, error, skipped) - Configuration: A mapping from role to a list of scanner types, or `LlamaFirewall.from_usecase` with `chatbot` or `coding_assistant`. Custom scanners register with `register_llamafirewall_scanner` - Models: `meta-llama/Llama-Prompt-Guard-2-86M`, gated on Hugging Face with manual review, under the Llama 4 Community Licence. Saved under `HF_HOME` after the first download - Outside calls: AlignmentCheck and the PII scanner post the trace to api.together.xyz through the `openai` client, with `TOGETHER_API_KEY`. The other four scanners make no network call after the model download - Command line: `llamafirewall configure` checks for the local model and the Together key, and can download the model - Integrations: Example scripts for the OpenAI Agents SDK guardrail hook and for LangChain with LangGraph - Telemetry: None found in the library source (searched 2026-10-08). The docs make no statement - Releases in 90 days: 0. The last upload was 1.0.3 on 2025-05-29 - Support: Issues at github.com/meta-llama/PurpleLlama. Security reports through Meta's bug bounty at bugbounty.meta.com - Scores: Reliability 53, Performance pending, Schema & documentation 49, Agent ergonomics 60, Security & auth 56, Payments & pricing 50, Task success pending, Maintenance & community 15, Transparency & trust 58 · total over the 7 assessed categories - Why: Reliability, Scored on the local-software lines, since the owner runs the library. · Schema & documentation, Framework reading. · Agent ergonomics, Read as a classifier an agent calls in process. · Security & auth, Read as software the owner runs. · Payments & pricing, Self-hosted rule, with one departure. · Maintenance & community, The last PyPI release is 1.0.3 on 29 May 2025, more than 16 months before the check (0 of 30). · Transparency & trust, The library is MIT. - Sources: 22, open questions: 7, both in the full twin - Capabilities: guard.injection, guard.pii, guard.policy, guard.self-host - JSON: https://www.anchorterminal.com/api/v1/tools/llamafirewall.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/llamafirewall.svg` or a link to https://www.anchorterminal.com/tools/llamafirewall from a page on llama.com or dev.meta.ai or one of their subdomains, or the README of github.com/meta-llama/PurpleLlama, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pin `huggingface_hub` below 1.0 and a matching `transformers` 4.x before importing the Prompt Guard scanner from the 1.0.3 wheel, or install from main 2. Get access to `meta-llama/Llama-Prompt-Guard-2-86M` and set a Hugging Face token first. Without one the loader prompts for a login and a headless run stalls 3. Call `scan_async` inside a running event loop. `scan()` wraps `asyncio.run` and fails there. `scan_async` returns score 0.0 and reason `default` on every allow 4. Split text longer than 512 tokens yourself before a Prompt Guard scan. The library truncates and does not chunk 5. Do not feed a block `reason` back to the model. The Prompt Guard reason quotes the full scanned text, and the hidden ASCII reason decodes the hidden payload ## Connect ```bash pip install llamafirewall llamafirewall configure ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | OpenAI Guardrails | B | 69.5 | guard.injection, guard.pii, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/openai-guardrails.min.md | | NVIDIA NeMo Guardrails | B | 68.4 | guard.injection, guard.pii, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/nemo-guardrails.min.md | | Lakera Guard (Check Point AI Guardrails) | C | 59.6 | guard.injection, guard.pii, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/lakera-guard.min.md | | Guardrails AI | D | 49.6 | guard.injection, guard.pii, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/guardrails-ai.min.md | | Google Cloud Model Armor | BB | 77.9 | guard.injection, guard.pii, guard.policy | https://www.anchorterminal.com/tools/google-model-armor.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)