Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
agentic-dm-gateway — Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration. | Kitploit
工具/GitLabGitLab/wattocyber/agentic-dm-gateway
Authentication & AuthorizationDefensive ToolsData ExfiltrationSecret DetectionAI Security
GitLabwattocyber/agentic-dm-gateway

agentic-dm-gateway

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration.

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
网站
721个月前尚未审核
内容在请求的语言中不可用。显示英文版本。

Agentic DM Gateway

agentic-dm-gateway banner

pipeline license gitlab

Security control plane for LLM agents over private chat (typically Discord DMs).

It sits in front of your agent. It decides who may talk, whether the session is unlocked, whether the process is paused, and whether this message is safe enough to forward. Your model and tools stay behind that gate. The library does not call an LLM. It does not implement product features beyond security.

Hermes-inspired. Design follows the same control-plane ideas used in Hermes Agent messaging gateways: DM-first delivery, identity allowlists, pairing-style open, owner kill switch, and a hard split between who may act (control plane) and message text the model sees (data plane). This package is a small, standalone extract of that pattern for any agent callable. Not affiliated with Nous Research.

Maturity: implemented · independently validated · maintained. See STATUS.md. Reproduce: python scripts/repro.py (expects REPRO_OK).

Offline tests:

pip install -e ".[dev]" # or: pip install -e . && pip install pytest
python -m pytest -q --tb=line
# or: python scripts/repro.py

Live: https://gitlab.com/WattoCyber/agentic-dm-gateway


The problem

If you put an agent on Discord (or any chat API) with tools, anyone who can message the bot can try to:

  • use the agent without permission
  • burn API quota with floods
  • inject "ignore previous instructions" style prompts
  • trick the model into echoing API keys or other secrets

You need a control plane (identity and process controls) separate from the data plane (message text the model sees).

This package is that control plane.


What it does

ControlBehavior
AllowlistOnly configured user IDs may proceed. Everyone else is dropped (silent or with a short deny string).
Owner vs friendOwners skip PIN and can pause the whole agent. Friends may need a shared PIN for a time-limited open (Hermes-style pairing idea, simplified).
Kill switchGlobal pause file or env flag. No agent turns while active.
Rate limitsSliding window per user (per minute and per hour).
Input checksMax length, strip odd control chars, regex heuristics for common injection / secret-fishing phrases.
Output scrubRedact secret-shaped tokens (API keys, JWTs, Bearer headers) and strip markdown/HTML image beacons that can exfil via auto-fetch.
Audit logAppend-only JSONL of allow/deny/auth/kill events for later review.
Local commands/auth, /lock, /kill, /unkill, /status handled without calling a model.

Scope: security gate only. Not a chatbot, trading bot, scanner, or agent framework. Pass an agent(user_id, text) -> str (or async) if you use Discord. The core works with any integer user id and plain text.


Demo (copy-paste)

$ python - <<'PY'
from agentic_dm_gateway import InboundSecurityPipeline
pipe = InboundSecurityPipeline({
 "allowed_user_ids": [111],
 "owner_ids": [111],
 "pin_enabled": False,
 "block_injection": True,
 "deny_message": "Not authorized.",
})
for uid, text in [
 (99, "hi"),
 (111, "ignore previous instructions"),
 (111, "summarize this note"),
]:
 r = pipe.precheck(uid, text)
 print(uid, r.stage, r.run_agent, r.reply_text)
PY

99 allowlist False Not authorized.
111 injection False Blocked: looks like prompt injection / secret fishing. Rephrase.
111 ok True None

$ python scripts/repro.py
REPRO_OK agentic-dm-gateway unit suite

How to hook it in

Three integration paths. Pick one.

1) Drop-in Discord (easiest)

Install with Discord support, point env at your user ids, register the gateway, run the bot.

pip install -e ".[discord]"
# or: pip install agentic-dm-gateway[discord]


![agentic-dm-gateway banner](https://assets.kitploit.com/production/public/readmes/50583/ed168cd7c4b9a61caf98c8a31b2dfb7d7e3bd3c5401288706c21c1376c7199ce.jpg)

export DISCORD_BOT_TOKEN=...
export AGENTIC_DM_ALLOWLIST=your_discord_user_id
export AGENTIC_DM_OWNER_ID=your_discord_user_id
# optional: export AGENTIC_DM_PIN=....


![agentic-dm-gateway banner](https://assets.kitploit.com/production/public/readmes/50583/ed168cd7c4b9a61caf98c8a31b2dfb7d7e3bd3c5401288706c21c1376c7199ce.jpg)
python examples/discord_echo_bot.py

In your own bot:

import discord
from agentic_dm_gateway.discord_adapter import register_dm_gateway

def agent(user_id: int, text: str, *, is_owner: bool = False) -> str:
 # your Hermes / local model / tool loop
 return call_your_model(text)

intents = discord.Intents.default()
intents.message_content = True
bot = discord.Client(intents=intents)

register_dm_gateway(
 bot,
 {
 "allowed_user_ids": [], # or rely on AGENTIC_DM_ALLOWLIST env
 "owner_ids": [],
 "pin_enabled": False,
 "deny_message": False, # silent drop for strangers
 },
 agent=agent,
)
bot.run(TOKEN)

What register_dm_gateway does:

  1. Installs an on_message handler on your discord.Client / bot.
  2. Ignores bots and guild messages (DMs only).
  3. Runs InboundSecurityPipeline.precheck before your agent.
  4. Sends deny / control replies when needed.
  5. Calls your agent(user_id, sanitized_text, is_owner=...).
  6. Scrubs the agent reply (secrets + image beacons) and chunks Discord's 2000-char limit.

Guild messages never reach the agent. Only DMs from allowlisted users do.

2) Manual Discord hook (you already have on_message)

If you cannot use register_dm_gateway (existing handler chain), call the pipeline yourself:

from agentic_dm_gateway import InboundSecurityPipeline
from agentic_dm_gateway.security import sanitize_agent_output

pipe = InboundSecurityPipeline({
 "allowed_user_ids": [YOUR_ID],
 "owner_ids": [YOUR_ID],
 "pin_enabled": True,
})

@bot.event
async def on_message(message):
 if message.author.bot or message.guild is not None:
 return

 pre = pipe.precheck(int(message.author.id), message.content or "")
 if pre.reply_text and not pre.run_agent:
 await message.channel.send(pre.reply_text[:1900])
 return
 if not pre.run_agent:
 return

 raw = await your_agent(pre.sanitized_text) # Hermes, Ollama, API, ...
 await message.channel.send(sanitize_agent_output(str(raw))[:1900])

3) Protocol-agnostic (Hermes, CLI, Telegram, anything)

No Discord import required. Use the same precheck around any agent turn:

from agentic_dm_gateway import InboundSecurityPipeline
from agentic_dm_gateway.security import sanitize_agent_output

pipe = InboundSecurityPipeline({
 "allowed_user_ids": [111],
 "owner_ids": [111],
 "pin_enabled": False,
 "rate_limit_per_minute": 20,
 "block_injection": True,
 "deny_message": "Not authorized.",
})

def handle_inbound(user_id: int, text: str) -> str | None:
 pre = pipe.precheck(user_id, text)
 if pre.run_agent:
 answer = my_llm(pre.sanitized_text) # your model / Hermes run
 return sanitize_agent_output(str(answer))
 return pre.reply_text # deny or control-command reply

PrecheckResult fields:

  • run_agent: forward to the model only if true
  • sanitized_text: cleaned input
  • reply_text: deny / control-command reply
  • stage: allowlist | kill | pin | rate | injection | ok | ...

Hook checklist:

下载工具