Skip to main content

EgressGuardProtocol

Defined in the secrets module.
AI Agent Contract for the wrapper’s secret-egress firewall. The real guard lives in the wrapper (praisonai): it inspects an outbound request, decides via the operator host allowlist whether a credential may leave, and either substitutes the sentinel for the real secret (:func:desentinelize) or refuses with an audited event. Core owns only this seam — no proxy, no host enforcement, no heavy imports — so a deployment can inject a guard without pulling anything heavy into core.

Methods

sentinel_for()

Instance method.

allow_egress()

Instance method.

Source

View on GitHub

praisonaiagents/secrets.py at line 485