Directory context | LLM Security and Red Teaming
AI-Scan-Interceptor
Self-hostable DLP gateway for enterprise prompts to ChatGPT/Claude/Gemini (Squid + Go ICAP + mTLS, AGPL-3.0)
Direct answer
What is AI-Scan-Interceptor?
AI-Scan-Interceptor is included in the Awesome MLSecOps LLM Security and Red Teaming directory. The community-maintained README describes it as: “Self-hostable DLP gateway for enterprise prompts to ChatGPT/Claude/Gemini (Squid + Go ICAP + mTLS, AGPL-3.0).” Its MLSecOps relevance is the testing or control of prompts, model behavior, retrieval paths, tool calls, outputs, or guardrails under adversarial input. The linked first-party source is the mshirakawa-ssp/ai-scan-interceptor repository on GitHub. A technical review should test the project's documented evidence across four criteria: Threat and model coverage, Reproducible evaluations, CI and reporting support, and Sensitive-data handling. Compare that evidence with the intended architecture and threat model. Catalog inclusion establishes relevance to this security category; it is not a certification, comparative ranking, or endorsement. Confirm current capabilities, maintenance, licensing, limitations, and deployment assumptions in the first-party documentation before adoption.
Self-hostable DLP gateway for enterprise prompts to ChatGPT/Claude/Gemini (Squid + Go ICAP + mTLS, AGPL-3.0)
Neutral catalog description synchronized from the Awesome MLSecOps README
Before adoption
What should teams verify about AI-Scan-Interceptor?
Answer these questions from current first-party documentation and testing evidence rather than relying on the directory listing alone.
- 01
Which models, APIs, RAG systems, or agent frameworks are explicitly supported?
- 02
Which prompt-injection, jailbreak, leakage, or tool-abuse scenarios are covered?
- 03
Are tests reproducible, versioned, and exportable to CI or reporting systems?
- 04
How are prompts, outputs, credentials, and other sensitive test data handled?