sha256:4d273c95c2ea55044b9c16c58a60bbcd2f792680ac62537445598129d503fb4d
Last pushed
8 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:4d273c95c2ea55044b9c16c58a60bbcd2f792680ac62537445598129d503fb4d
schemaVersion: "3"
displayName: Mend Guardrails
description: Runs mend-guardrails-server on loopback and points Codex/OpenAI-compatible agents at it via OPENAI_BASE_URL so prompt bodies are inspected (secrets, PII, prompt injection) before they reach the model. Also exposes /v1/guard/* and mend-guard-text for scanning MCP and tool-result text.
sourceUrl: https://github.com/docker/sbx-kits-contrib
version: 1.0.0
licenses:
- Apache-2.0
kind: mixin
requires:
- codex
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
install:
allow:
- '*.mend.io'
- mend.io
- pypi.org
- files.pythonhosted.org
- github.com
- objects.githubusercontent.com
- release-assets.githubusercontent.com
runtime:
allow:
- '*.mend.io'
- mend.io
- type: com.docker.sandbox/lifecycle@1
config:
install:
- command: |
set -euo pipefail
if ! command -v python3 >/dev/null 2>&1; then
echo "mend-guardrails kit requires python3 >= 3.11" >&2
exit 1
fi
python3 -c 'import sys; sys.exit(0 if sys.version_info >= (3, 11) else 1)' \
|| { echo "mend-guardrails kit requires python3 >= 3.11" >&2; exit 1; }
description: Check python3 >= 3.11
- command: |
set -euo pipefail
SRC='${{ kit.args.pythonSrc }}'
if [ -n "$SRC" ]; then
if [ ! -d "$SRC" ] || [ ! -f "$SRC/pyproject.toml" ]; then
echo "mend-guardrails: pythonSrc='$SRC' must be a mounted checkout with pyproject.toml" >&2
echo "mend-guardrails: pass it as an extra sbx workspace (not :ro), e.g." >&2
echo " sbx run ... --kit-arg mend-guardrails.pythonSrc=\"\$SRC\" . \"\$SRC\"" >&2
exit 1
fi
echo "pip install -e ${SRC}[server] (local source; deps from PyPI/GitHub)"
python3 -m pip install --break-system-packages \
--progress-bar on --timeout 120 --retries 5 \
-e "${SRC}[server]"
elif [ -n "${MEND_KEY:-}" ]; then
echo "pip install mend-guardrails[server]>=0.0.18b0 (PyPI, Mend extra-index, spaCy)"
enc=$(python3 -c 'import os,urllib.parse; print(urllib.parse.quote(os.environ["MEND_KEY"], safe=""))')
python3 -m pip install --break-system-packages \
--progress-bar on --timeout 120 --retries 5 \
--extra-index-url "https://mend:${enc}@downloads.mend.io/guardrails/" \
'mend-guardrails[server]>=0.0.18b0'
else
# MEND_KEY is a runtime secret. It is absent during secret-less
# validation, so skip cleanly and let startup report the missing
# server when the sandbox was created without the key.
echo "mend-guardrails: MEND_KEY not set; skipping server install." >&2
echo "mend-guardrails: create the sandbox with 'sbx run -e MEND_KEY=...' to install the server." >&2
fi
description: pip install mend-guardrails[server] (when MEND_KEY / pythonSrc present)
env:
- MEND_KEY
- HTTP_PROXY
- HTTPS_PROXY
- command: |
set -euo pipefail
chmod +x /home/agent/.local/bin/mend-guard-text \
/home/agent/.local/bin/mend-guardrails-sandbox-start \
/home/agent/.local/bin/mend-guardrails-configure-codex \
/home/agent/.local/bin/mend-guardrails-selftest \
/home/agent/.local/bin/curl
/home/agent/.local/bin/mend-guardrails-configure-codex
AGENT_ENV=/home/agent/.mend-guardrails/agent-env.sh
for rc in /home/agent/.profile /home/agent/.bashrc /home/agent/.zshrc; do
touch "$rc"
grep -q 'mend-guardrails/agent-env.sh' "$rc" 2>/dev/null || \
printf '\n# Mend Guardrails\n. %s\n' \
"$AGENT_ENV" >> "$rc"
done
if [ -d /etc/profile.d ]; then
printf '. %s\n' "$AGENT_ENV" > /etc/profile.d/mend-guardrails-noproxy.sh
fi
command -v mend-guardrails-server \
|| echo "mend-guardrails: server not installed yet (create the sandbox with MEND_KEY via 'sbx run -e')." >&2
description: chmod helpers, Codex config, shell rc hooks
env:
- MEND_GUARDRAILS_INTERCEPT_TUI
- CODEX_HOME
startup:
- background: true
command:
- /home/agent/.local/bin/mend-guardrails-sandbox-start
description: Start mend-guardrails-server on 127.0.0.1:8787
env:
- MEND_KEY
- MEND_GUARDRAILS_KEY
- MEND_GUARDRAILS_INTERCEPT_TUI
- MEND_GUARDRAILS_FORWARD_HEADERS
- MEND_GUARDRAILS_POLICY_DIR
- MEND_GUARDRAILS_DEFAULT_CONFIG_ID
- MEND_GUARDRAILS_INSTANCE_NAME
- MEND_GUARDRAILS_OFFLINE
- MEND_GUARDRAILS_POLICY_SOURCE
- CODEX_HOME
- OPENAI_BASE_URL
- OPENAI_API_KEY
- OPENAI_MODEL
- HTTP_PROXY
- HTTPS_PROXY
- NO_PROXY
- no_proxy
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/mend-guardrails/mend-guardrails-context.md
args:
interceptTui:
default: "false"
description: Opt in to route Codex TUI model calls through loopback Guardrails (user-level model_provider=mend_guardrails). Default false keeps ChatGPT subscription TUI auth. When true, requires a host OpenAI platform API key with api.responses.write (and billing), plus an API model name (not Sol/Luna-only ChatGPT catalog).
enum:
- "false"
- "true"
env: MEND_GUARDRAILS_INTERCEPT_TUI
offline:
default: "false"
description: 'Set MEND_GUARDRAILS_OFFLINE. Default false (online: platform registration and telemetry). Use true with policySource=local so the SDK can load the kit sandbox.json. MEND_KEY is still required. Do not combine with policySource=api.'
enum:
- "false"
- "true"
env: MEND_GUARDRAILS_OFFLINE
policySource:
default: api
description: Default api loads the org policy from the Mend Platform (use with offline=false). Enable detectors in the platform policy as needed. Opt in to local for the kit sandbox.json file (startup then sets offline=true).
enum:
- local
- api
env: MEND_GUARDRAILS_POLICY_SOURCE
pythonSrc:
default: ""
description: Absolute path to a local mend-guardrails-python checkout for editable install instead of the Mend downloads wheel. Empty (default) installs from PyPI + downloads.mend.io. Mount the same path as an extra sbx workspace (not :ro) so install can write egg-info.