
LLMVerify
io.github.subodhkcv1.8.0更新于 Oct 9, 2026
Local-first MCP server for LLM output verification — risk signals, injection and PII checks.
概览
本地 MCP 服务器,用于检查 LLM 输出的幻觉风险、提示注入和 PII,并可对敏感数据做脱敏。
- 功能
- LLMVerify 通过 stdio 向兼容 MCP 的智能体暴露一个本地验证引擎。它提供六个工具:verify_llm_content、assess_hallucination_risk、check_prompt_injection、check_pii、redact_pii 和 get_llmverify_capabilities。检查基于确定性的模式匹配,覆盖幻觉与一致性信号、注入与越狱模式,以及邮箱、电话号码、SSN、信用卡和常见 API 密钥等标准 PII 格式。结果会附带明确的 limitations 或 notChecked 列表。
- 适用场景
- 当助手需要处理不可信的用户输入或模型输出,并希望在内容到达用户或日志之前加一道本地防护时使用。适合对注入尝试做初步筛查、PII 检测与脱敏,不适合做事实核验或审批决策。
- 运行要求
- 通过 npx 从 npm 包 llmverify 在本地运行;MCP 命令需要 Node.js 20 或更高版本。无需账号或 API 密钥,免费版不发起网络请求。可选环境变量用于配置审计、基线、日志和状态目录,以及输入输出大小上限和单工具超时。
安装
在 SourceWeft 中
- 打开 控制台中的 LLMVerify,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
llmverify
You shipped an AI feature. Your LLM hallucinated a citation, leaked a customer's email, and followed a prompt-injection buried in user input — on the same day. llmverify is the safety layer that sits between your LLM and your users.
Local-first verification, PII redaction, prompt-injection defense, and runtime monitoring for any LLM. One npm install. Zero telemetry. No API keys on the free tier.
[npm version] [CI] [License: MIT]
Last Updated: August 21, 2026 Version: 1.7.0 Node: >= 18.0.0 License: MIT
Links
- Product page: haiec.com/llmverify
- npm: npmjs.com/package/llmverify
- GitHub: github.com/subodhkc/llmverify-npm
- Python (placeholder): pypi.org/project/llmverify — namespace reservation, not a port of this package
- Author: Subodh Kc
The problem
You build with GPT-4, Claude, Gemini, or any LLM. The model:
- Hallucinates facts and citations that do not exist.
- Leaks PII — emails, phone numbers, SSNs, API keys in responses.
- Follows prompt injections — users trick it into ignoring your instructions.
- Returns broken JSON that crashes your parser.
- Drifts in quality over time, and nobody notices until a user complains.
You need a guardrail between the model and your users. That is llmverify.
Install
Everything runs locally. The free tier makes zero network requests and needs no API key. Free tier limit: 500 verification calls per day (tracked locally, never sent anywhere).
What you get
Quick start (30 seconds)
Three lines of safety between your LLM and your users. No config file required. No API key required.
How it works
llmverify runs deterministic, pattern-based engines locally — no model calls, no network on the free tier. Same input plus same rules equals same result. Every result carries an explicit limitations array stating what was and was not checked, so you never mistake a clean score for a guarantee.
Framework alignment (baseline mapping only — not certification):
- OWASP LLM Top 10
- NIST AI RMF
- EU AI Act
- ISO 42001
- CSM6 (HAIEC's 38-rule control set)
CLI
The server binds to 127.0.0.1 by default, restricts CORS to localhost origins, and rate-limits clients (100 requests / 60s). It requires express (an optional dependency that installs by default).
MCP server
llmverify ships a built-in Model Context Protocol server — the same engine, exposed to MCP-compatible agents and IDEs over stdio:
Six tools: verify_llm_content, assess_hallucination_risk, check_prompt_injection, check_pii, redact_pii, get_llmverify_capabilities. Stdio-only, zero outbound network, bounded inputs/outputs, PII-filtered responses, honest notChecked/audit semantics.
Requires Node.js ≥ 20 (the MCP SDK's floor; the rest of the package supports ≥ 18). The MCP SDK and zod are regular dependencies — the mcp command lazy-loads them so other commands pay no startup cost.
See docs/MCP.md for the full tool reference and security model.
Limitations
llmverify is a triage tool, not a truth oracle. Be honest with yourself about what it can and cannot do:
- It cannot definitively prove hallucinations. Hallucination signals are pattern-based. "The capital of France is London" scores low because the text looks internally consistent. Ground-truth verification requires a source document you provide.
- It does not replace human review. Use it to triage, not to approve.
- PII detection is regex-based. It catches standard formats (emails, US phones, SSNs, credit cards, common API keys). It misses obfuscated, image-embedded, or encoded PII. Accuracy is roughly 90% for standard formats, lower for variations.
- Prompt-injection detection is pattern-based. Novel or obfuscated injections can evade it.
- Free tier is 100% local. ML-enhanced features require a paid tier and an explicit API key; the free tier never makes network requests and never sends data anywhere.
If a claim matters, verify it yourself. llmverify narrows the risk surface; it does not eliminate it.
Documentation
Part of HAIEC
llmverify is part of the HAIEC (Human AI Evidence Company) AI governance platform. Use it alongside the AI Security Scanner, the CI/CD pipeline integration, and Runtime Injection Testing.
Support
- Issues: GitHub Issues
- Docs: Full documentation
License
MIT — see LICENSE.
Recommendation (not legal advice): Run verify() on every model output that reaches a user, and isInputSafe() on every user input that reaches a model. Treat the risk level as a triage signal, not an approval.
来源:README.md,提交 2d130f6
工具
0版本历史
1- v1.8.0最新Oct 9, 2026


