zn-gate (local)
Secret redaction
Mask credentials in tool outputs before they reach the model or the user.
Cette page n’est pas encore traduite. Vous lisez la version anglaise.
Tools often return more than they should: API responses with keys, files with tokens, sub-agent output with credentials. zn-gate can mask them before the text goes back into the model context.
Mask a guarded tool's output
from zn_gate import guard
@guard(mask_secrets=True)
def fetch_credentials():
return "API response: sk-proj-1234567890abcdef..."
print(fetch_credentials())
# API response: [REDACTED_OPENAI_KEY]
Sanitize any payload
from zn_gate import redact_secrets, sanitize_tool_result
redacted_text, found = redact_secrets(raw_text)
print(redacted_text, len(found), "secrets masked")
clean = sanitize_tool_result("db_query", untrusted_output)
if clean["safe_to_ingest"]:
llm.invoke(clean["sanitized_content"])
sanitize_tool_result both masks secrets and checks the output for indirect prompt injection, so a poisoned web page or database row is flagged before the model reads it.