Security handler#140
Open
surendra84 wants to merge 3 commits into
Open
Conversation
|
|
| @@ -0,0 +1,174 @@ | |||
| """security_handler — Generic LLM security utilities for agent pipelines. | |||
Contributor
There was a problem hiding this comment.
if it's AI specific, security handler is too generic.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Added a new
security_handlermodule to the SAP Cloud SDK for Python. This module provides input validation and sanitizationutilities to help developers protect their applications from injection attacks and malicious input when building AI-powered
applications on SAP BTP.
The module includes:
SecurityHandler— orchestrator that runs guardrails and injection detection, returning a ScanResultInjectionDetector— detects prompt injection, SQL injection, XSS, and path traversal patternsForbiddenPatternGuardrail— configurable regex-based content guardrailsanitize()— strips dangerous characters and enforces input length limitsescape_xml_tags()— escapes XML/HTML tags in user inputScanResult, Violation, Severity— result models for structured security scan outputRelated Issue
Closes #<issue_number>
(Link to the GitHub issue this PR addresses)
Type of Change
Please check the relevant option:
How to Test
Describe how reviewers can test your changes:
uv run pytest tests/security_handler/Checklist
Before submitting your PR, please review and check the following:
src/sap_cloud_sdk/security_handler/user-guide.md and README.md)Breaking Changes
None. This is a purely additive new module with no changes to existing APIs.
Additional Notes
__init__.pywith__all__src/sap_cloud_sdk/security_handler/user-guide.mdAdd any additional context, screenshots, or information that would help reviewers.