| Developed by | Guardrails AI | | Date of development | Feb 15, 2024 | | Validator type | Format | | Blog | | | License | Apache 2 | | Input/Output | Output |
Scans LLM outputs for strings that could cause browser script execution downstream. Uses the bleach
library to detect and escape suspect characters.
Use this validator when you are passing the results of your LLM requests directly to a browser or other html-executable environment. It's a good idea to also implement other XSS and code injection prevention techniques.
- Dependencies:
bleach
- guardrails-ai>=0.4.0
$ guardrails hub install hub://guardrails/web_sanitization
In this example, we apply the validator to a string output generated by an LLM.
# Import Guard and Validator
from guardrails import Guard
from guardrails.hub import WebSanitization
# Use the Guard with the validator
guard = Guard().use(WebSanitization, on_fail="exception")
# Test passing response
guard.validate(
"""MetaAI's Llama2 is the latest in their open-source LLM series.
It is a powerful language model."""
)
try:
# Test failing response
guard.validate(
"""MetaAI's Llama2 is the latest in their open-source LLM series.
It is a powerful language model. <script>alert('XSS')</script>"""
)
except Exception as e:
print(e)
Output:
Validation failed for field with errors: The output contains a web injection attack.
__init__(self, on_fail="noop")
on_fail
(str, Callable): The policy to enact when a validator fails. Ifstr
, must be one ofreask
,fix
,filter
,refrain
,noop
,exception
orfix_reask
. Otherwise, must be a function that is called when the validator fails.
Initializes a new instance of the WebSanitization validator class.
Parameters:
validate(self, value, metadata={}) -> ValidationResult
- This method should not be called directly by the user. Instead, invoke
guard.parse(...)
where this method will be called internally for each associated Validator. - When invoking
guard.parse(...)
, ensure to pass the appropriatemetadata
dictionary that includes keys and values required by this validator. Ifguard
is associated with multiple validators, combine all necessary metadata into a single dictionary. value
(Any): The input value to validate.metadata
(dict): A dictionary containing metadata required for validation. Keys and values must match the expectations of this validator.
Validates the given value
using the rules defined in this validator. This method is automatically invoked by guard.parse(...)
, ensuring the validation logic is applied to the input data.
Note:
Parameters:
Metadata is not used in this validator