Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
agentic-dm-gateway — Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration. | Kitploit
Ferramentas/GitLabGitLab/wattocyber/agentic-dm-gateway
Authentication & AuthorizationDefensive ToolsData ExfiltrationSecret DetectionAI Security
GitLabwattocyber/agentic-dm-gateway

agentic-dm-gateway

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration.

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Ver Repositório
Site
70há 1 mêsAinda não revisado
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Agentic DM Gateway

agentic-dm-gateway banner

pipeline license gitlab

Security control plane for LLM agents over private chat (typically Discord DMs).

It sits in front of your agent. It decides who may talk, whether the session is unlocked, whether the process is paused, and whether this message is safe enough to forward. Your model and tools stay behind that gate. The library does not call an LLM. It does not implement product features beyond security.

Hermes-inspired. Design follows the same control-plane ideas used in Hermes Agent messaging gateways: DM-first delivery, identity allowlists, pairing-style open, owner kill switch, and a hard split between who may act (control plane) and message text the model sees (data plane). This package is a small, standalone extract of that pattern for any agent callable. Not affiliated with Nous Research.

Maturity: implemented · independently validated · maintained. See STATUS.md. Reproduce: python scripts/repro.py (expects REPRO_OK).

Offline tests:

pip install -e ".[dev]" # or: pip install -e . && pip install pytest
python -m pytest -q --tb=line
# or: python scripts/repro.py

Live: https://gitlab.com/WattoCyber/agentic-dm-gateway


The problem

If you put an agent on Discord (or any chat API) with tools, anyone who can message the bot can try to:

  • use the agent without permission
  • burn API quota with floods
  • inject "ignore previous instructions" style prompts
  • trick the model into echoing API keys or other secrets

You need a control plane (identity and process controls) separate from the data plane (message text the model sees).

This package is that control plane.


What it does

ControlBehavior
AllowlistOnly configured user IDs may proceed. Everyone else is dropped (silent or with a short deny string).
Owner vs friendOwners skip PIN and can pause the whole agent. Friends may need a shared PIN for a time-limited open (Hermes-style pairing idea, simplified).
Kill switchGlobal pause file or env flag. No agent turns while active.
Rate limitsSliding window per user (per minute and per hour).
Input checksMax length, strip odd control chars, regex heuristics for common injection / secret-fishing phrases.
Output scrubRedact secret-shaped tokens (API keys, JWTs, Bearer headers) and strip markdown/HTML image beacons that can exfil via auto-fetch.
Audit logAppend-only JSONL of allow/deny/auth/kill events for later review.
Local commands/auth, /lock, /kill, /unkill, /status handled without calling a model.

Scope: security gate only. Not a chatbot, trading bot, scanner, or agent framework. Pass an agent(user_id, text) -> str (or async) if you use Discord. The core works with any integer user id and plain text.


Demo (copy-paste)

$ python - <<'PY'
from agentic_dm_gateway import InboundSecurityPipeline
pipe = InboundSecurityPipeline({
 "allowed_user_ids": [111],
 "owner_ids": [111],
 "pin_enabled": False,
 "block_injection": True,
 "deny_message": "Not authorized.",
})
for uid, text in [
 (99, "hi"),
 (111, "ignore previous instructions"),
 (111, "summarize this note"),
]:
 r = pipe.precheck(uid, text)
 print(uid, r.stage, r.run_agent, r.reply_text)
PY

99 allowlist False Not authorized.
111 injection False Blocked: looks like prompt injection / secret fishing. Rephrase.
111 ok True None

$ python scripts/repro.py
REPRO_OK agentic-dm-gateway unit suite

How to hook it in

Three integration paths. Pick one.

1) Drop-in Discord (easiest)

Install with Discord support, point env at your user ids, register the gateway, run the bot.

pip install -e ".[discord]"
# or: pip install agentic-dm-gateway[discord]


![agentic-dm-gateway banner](https://assets.kitploit.com/production/public/readmes/50583/ed168cd7c4b9a61caf98c8a31b2dfb7d7e3bd3c5401288706c21c1376c7199ce.jpg)

export DISCORD_BOT_TOKEN=...
export AGENTIC_DM_ALLOWLIST=your_discord_user_id
export AGENTIC_DM_OWNER_ID=your_discord_user_id
# optional: export AGENTIC_DM_PIN=....


![agentic-dm-gateway banner](https://assets.kitploit.com/production/public/readmes/50583/ed168cd7c4b9a61caf98c8a31b2dfb7d7e3bd3c5401288706c21c1376c7199ce.jpg)
python examples/discord_echo_bot.py

In your own bot:

import discord
from agentic_dm_gateway.discord_adapter import register_dm_gateway

def agent(user_id: int, text: str, *, is_owner: bool = False) -> str:
 # your Hermes / local model / tool loop
 return call_your_model(text)

intents = discord.Intents.default()
intents.message_content = True
bot = discord.Client(intents=intents)

register_dm_gateway(
 bot,
 {
 "allowed_user_ids": [], # or rely on AGENTIC_DM_ALLOWLIST env
 "owner_ids": [],
 "pin_enabled": False,
 "deny_message": False, # silent drop for strangers
 },
 agent=agent,
)
bot.run(TOKEN)

What register_dm_gateway does:

  1. Installs an on_message handler on your discord.Client / bot.
  2. Ignores bots and guild messages (DMs only).
  3. Runs InboundSecurityPipeline.precheck before your agent.
  4. Sends deny / control replies when needed.
  5. Calls your agent(user_id, sanitized_text, is_owner=...).
  6. Scrubs the agent reply (secrets + image beacons) and chunks Discord's 2000-char limit.

Guild messages never reach the agent. Only DMs from allowlisted users do.

2) Manual Discord hook (you already have on_message)

If you cannot use register_dm_gateway (existing handler chain), call the pipeline yourself:

from agentic_dm_gateway import InboundSecurityPipeline
from agentic_dm_gateway.security import sanitize_agent_output

pipe = InboundSecurityPipeline({
 "allowed_user_ids": [YOUR_ID],
 "owner_ids": [YOUR_ID],
 "pin_enabled": True,
})

@bot.event
async def on_message(message):
 if message.author.bot or message.guild is not None:
 return

 pre = pipe.precheck(int(message.author.id), message.content or "")
 if pre.reply_text and not pre.run_agent:
 await message.channel.send(pre.reply_text[:1900])
 return
 if not pre.run_agent:
 return

 raw = await your_agent(pre.sanitized_text) # Hermes, Ollama, API, ...
 await message.channel.send(sanitize_agent_output(str(raw))[:1900])

3) Protocol-agnostic (Hermes, CLI, Telegram, anything)

No Discord import required. Use the same precheck around any agent turn:

from agentic_dm_gateway import InboundSecurityPipeline
from agentic_dm_gateway.security import sanitize_agent_output

pipe = InboundSecurityPipeline({
 "allowed_user_ids": [111],
 "owner_ids": [111],
 "pin_enabled": False,
 "rate_limit_per_minute": 20,
 "block_injection": True,
 "deny_message": "Not authorized.",
})

def handle_inbound(user_id: int, text: str) -> str | None:
 pre = pipe.precheck(user_id, text)
 if pre.run_agent:
 answer = my_llm(pre.sanitized_text) # your model / Hermes run
 return sanitize_agent_output(str(answer))
 return pre.reply_text # deny or control-command reply

PrecheckResult fields:

  • run_agent: forward to the model only if true
  • sanitized_text: cleaned input
  • reply_text: deny / control-command reply
  • stage: allowlist | kill | pin | rate | injection | ok | ...

Hook checklist:

Baixar ferramenta