Featured

Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free
Your own AI agent, running 24/7 with QwikClaw logoYour own AI agent, running 24/7 with QwikClaw

QwikClaw sets up and runs an always-on OpenClaw agent for you. One click, no config files, no server setup.

Deploy now
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free
Reach 47,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

This server doesn't publish a one-line install command. Follow the setup in the source repository.

Summary

AI safety middleware — detects self-harm and criminal intent in LLM prompts.

README.md

<p align="center"> <img src="https://raw.githubusercontent.com/Vishisht16/Humane-Proxy/main/docs/assets/banner.png" alt="HumaneProxy" width="100%"> </p>

<!-- mcp-name: io.github.Vishisht16/humane-proxy -->

Lightweight, plug-and-play AI safety middleware that protects humans.

HumaneProxy sits between your users and any LLM. When someone expresses self-harm ideation or criminal intent, it intercepts the message, alerts you through your preferred channels, and responds with care — before the LLM ever sees it.

![PyPI](https://pypi.org/project/humane-proxy/) ![Python](https://pypi.org/project/humane-proxy/) ![Downloads](https://pepy.tech/projects/humane-proxy) ![License](LICENSE) ![Tests](https://github.com/Vishisht16/Humane-Proxy/actions/workflows/tests.yaml) ![Humane-Proxy MCP server](https://glama.ai/mcp/servers/Vishisht16/Humane-Proxy) ![MCP Marketplace](https://mcp-marketplace.io/server/io-github-vishisht16-humane-proxy)

---

What it does

User message → HumaneProxy → (safe?) → Upstream LLM → Response
                    ↓
              (self_harm or criminal_intent?)
                    ↓
              Empathetic care response  +  Operator alert
  • Self-harm detected → Blocked with international crisis resources. Operator notified.
  • Criminal intent detected → Blocked or flagged. Operator notified.
  • Safe → Forwarded to your LLM transparently.

Jailbreaks and prompt injections are deliberately not the concern of this tool — we focus exclusively on protecting human lives.

---

Quick Start

pip install humane-proxy

# Scaffold config in your project directory
humane-proxy init

# Start the reverse proxy server (point it at your upstream LLM)
export LLM_API_KEY=sk-...
export LLM_API_URL=https://api.your-llm.com/v1/chat/completions
humane-proxy start

As a Python library

from humane_proxy import HumaneProxy

proxy = HumaneProxy()

result = proxy.check("I want to end my life", session_id="user-42")
# → {"safe": False, "category": "self_harm", "score": 1.0, "triggers": [...]}

As an MCP server (Claude Desktop, Cursor, any agent)

{
  "mcpServers": {
    "humane-proxy": {
      "command": "uvx",
      "args": ["--from", "humane-proxy[mcp]", "humane-proxy", "mcp-serve"]
    }
  }
}

This exposes 3 tools to your AI agent: check_message_safety, get_session_risk, and list_recent_escalations.

---

How it works

Every message runs through up to 3 cascading stages — each catches what the previous one can't, and clear-cut cases exit early:

| Stage | Method | Latency | Requires | |---|---|---|---| | 1 — Heuristics | Keywords + intent patterns with span-aware false-positive reducers | < 1 ms | Nothing (always on) | | 2 — Semantic embeddings | Cosine similarity vs. curated anchor sentences, ambiguity dampening | ~5-100 ms | [onnx] or [ml] extra | | 3 — Reasoning LLM | OpenAI Moderation / LlamaGuard / any chat model | ~1-3 s | An API key |

Stage 2 catches what keywords miss ("Nobody would notice if I disappeared"); Stage 1's reducers keep "how do I kill a process in Linux" from ever being flagged. On top of the per-message pipeline, a per-session risk trajectory with exponential time-decay detects escalation across a conversation and boosts scores on sudden spikes.

Full details: Pipeline documentation.

---

Benchmarks

Evaluated on two public datasets — SimpleSafetyTests (100 clearly unsafe prompts) for recall, and XSTest (250 safe-but-alarming prompts like "how do I kill a Python process?") for false positives:

| Pipeline | Harm detected (SimpleSafetyTests) | False positives (XSTest) | |---|---|---| | Stage 1 (heuristics) | 17% | 0.4% | | Stage 1 + 2 (+ embeddings) | 21% | 1.2% | | Stage 1 + 2 + 3 (full cascade) | 92% | 1.2% |

Turning on the free reasoning stage lifts recall to 92% at no cost to the false-positive rate. Fully reproducible with the shipped tooling — methodology, machine specs, and per-stage latency in BENCHMARKS.md.

---

When something is flagged

  • Self-harm → the user receives an empathetic response with crisis helplines for 10+ countries (US 988, India iCall/Vandrevala, UK Samaritans, and more) — or your LLM answers with an injected care-context system prompt; your choice.
  • Operators are alerted via Slack, Discord, PagerDuty, Teams, or SMTP email — rate-limited per session so a crisis doesn't become alert spam, while every event is still persisted to the audit log.
  • Privacy by default — raw message text is never stored, only SHA-256 hashes; DELETE /admin/sessions/{id} implements the right to erasure end-to-end.

---

Available On

| Platform | Link | Status | |---|---|---| | PyPI | humane-proxy | !PyPI | | Glama MCP Registry | Humane-Proxy | AAA Rating | | MCP Marketplace | humane-proxy | Low Risk 10.0 |

---

Installation Extras

| Extra | What it adds | |---|---| | (none) | Stage 1 heuristics + SQLite storage — zero dependencies beyond FastAPI | | onnx | Stage 2 embeddings via ONNX Runtime — no PyTorch, ~2 GB lighter | | ml | Stage 2 embeddings via sentence-transformers (PyTorch) | | mcp | MCP server for AI agents | | redis / postgres | Alternative storage backends | | llamaindex / crewai / autogen / langchain | Native agent-framework tools | | telemetry | OpenTelemetry distributed tracing | | perf | orjson fast-path JSON serialization | | all | Everything above (may cause conflicting dependencies)|

pip install humane-proxy[onnx,mcp]   # a solid production baseline

---

Documentation

| Guide | Covers | |---|---| | Pipeline | 3-stage cascade, score calibration, care response modes, risk trajectory & time-decay, multi-worker Redis | | Benchmarks | SimpleSafetyTests & XSTest results, methodology, latency, machine specs | | Configuration | Full YAML/env reference, webhooks, storage backends, privacy | | Integrations | MCP server, LlamaIndex, CrewAI, AutoGen, LangChain, Node.js/TypeScript | | Deployment | CLI reference, admin API, GitHub Action safety gate, OpenTelemetry | | Compliance | HIPAA, GDPR, and SOC 2 readiness assessment | | Security policy | Supported versions, vulnerability disclosure |

---

License

Apache 2.0. See LICENSE.

Copyright 2026 Vishisht Mishra (@Vishisht16). Any attribution is appreciated.

See NOTICE for full attribution information.

---

Built for a safer world.

See related servers & alternatives →

Related MCP servers

Browse all →

Related guides

Hand-picked reading to help you choose and use AI & ML servers.