
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
@safeprompt.dev/langchain
Advanced tools
LangChain integration for SafePrompt: prompt-injection detection as a callback handler. Validates every prompt flowing through a chain before it reaches the LLM.
LangChain callback handler that validates every prompt flowing through your chain via the SafePrompt API before it reaches the LLM. Catches jailbreaks, data-extraction attempts, authority-signal impersonation, and indirect injection from tool outputs.
npm install @safeprompt.dev/langchain
Peer dependency: @langchain/core (LangChain 1.x, >=1.0.0).
import { LLMChain } from 'langchain/chains';
import { ChatOpenAI } from '@langchain/openai';
import { PromptTemplate } from '@langchain/core/prompts';
import { SafePromptCallbackHandler, SafePromptBlockedError } from '@safeprompt.dev/langchain';
const chain = new LLMChain({
llm: new ChatOpenAI({ model: 'gpt-4o-mini' }),
prompt: PromptTemplate.fromTemplate('Answer: {input}'),
callbacks: [
new SafePromptCallbackHandler({
apiKey: process.env.SAFEPROMPT_API_KEY!,
userIP: req.ip, // end-user IP from your web framework
}),
],
});
try {
const { text } = await chain.call({ input: userInput });
console.log(text);
} catch (err) {
if (err instanceof SafePromptBlockedError) {
return res.status(400).json({
error: 'Prompt blocked for safety',
threats: err.result.threats,
});
}
throw err;
}
new SafePromptCallbackHandler({
apiKey: 'sp_live_…',
userIP: '203.0.113.1', // REQUIRED — end-user IP
provider: 'https://api.safeprompt.dev', // default
mode: 'balanced', // 'fast' | 'balanced' | 'strict'
enforcement: 'block', // 'block' | 'log' (log = don't throw, just fire onBlock)
onProviderError: 'fail-closed', // 'fail-closed' | 'fail-open'
sampleRate: 1.0, // 0..1 — fraction of prompts to validate
onBlock: (prompt, result) => {
console.warn('[safeprompt] blocked', result.threats, '→', prompt.slice(0, 80));
},
onError: (prompt, err) => {
console.error('[safeprompt] provider error', err.message);
},
});
enforcement: 'log' — tune before enforcingRun the adapter in log mode in staging/production for a week. You get onBlock events
without any chain aborts. Review the results in your logs (or SafePrompt dashboard), tune
custom lists / confidence threshold, then flip enforcement: 'block'.
sampleRate — cost control for high-volume appsEach validation call is a round-trip to the SafePrompt API (sub-second for most prompts,
but still a network hop). For apps processing >10K prompts/day where latency matters more
than per-prompt coverage, set sampleRate: 0.1 to validate 10% of prompts.
When you use this handler with a LangChain agent, it also fires on handleToolEnd — the
moment a tool returns content that will be fed back to the LLM. This is the key protection
against indirect prompt injection (content fetched from the web, retrieved from RAG, etc.,
that hides malicious instructions).
handleLLMStart / handleChatModelStart fires before every LLM call. Each prompt is
POSTed to the SafePrompt API.safe: false, the handler either throws SafePromptBlockedError
(in block mode) or fires your onBlock hook (in log mode).handleToolEnd applies the same check to agent tool outputs — the primary indirect
injection surface.SAFEPROMPT_API_KEY.userIP. The API
requires this for threat-intelligence tracking. Use your web framework's IP helper
(req.ip in Express, req.socket.remoteAddress, etc.).enforcement: 'log', inspect the blocked prompts, and
use custom whitelist rules on your SafePrompt account to allow known-safe patterns.MIT.
FAQs
LangChain integration for SafePrompt: prompt-injection detection as a callback handler. Validates every prompt flowing through a chain before it reaches the LLM.
The npm package @safeprompt.dev/langchain receives a total of 7 weekly downloads. As such, @safeprompt.dev/langchain popularity was classified as not popular.
We found that @safeprompt.dev/langchain demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.