EgressGuardProtocol
Defined in the secrets module.AI Agent Contract for the wrapper’s secret-egress firewall. The real guard lives in the wrapper (
praisonai): it inspects an
outbound request, decides via the operator host allowlist whether a
credential may leave, and either substitutes the sentinel for the real
secret (:func:desentinelize) or refuses with an audited event. Core owns
only this seam — no proxy, no host enforcement, no heavy imports — so a
deployment can inject a guard without pulling anything heavy into core.
Methods
sentinel_for()
Instance method.
allow_egress()
Instance method.
Source
View on GitHub
praisonaiagents/secrets.py at line 485
