Prompt Shield & AI Safety MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| BASE_RPC_URL | Yes | The Base L2 RPC URL. | |
| PAYMENT_WALLET | Yes | The recipient payout wallet address on Base. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| prompt_injection_jailbreak_classifierA | High-speed deterministic classifier detecting indirect prompt injections, delimiter hijacking, and system role impersonation attacks in user inputs. (0.045 USDC on Base L2) |
| strip_prompt_injectionA | Neutralizes indirect prompt injections, system prompt leak probes, jailbreak tokens, and hidden instruction tags in untrusted text. (0.02 USDC on Base L2) |
| secrets_entropy_scannerB | Shannon entropy and pattern analyzer scanning source code for leaked private keys, AWS access secrets, JWTs, and database connection strings. (0.030 USDC on Base L2) |
| obfuscate_pii_entitiesA | Detects and masks Personally Identifiable Information (SSNs, credit cards, emails, phone numbers, API keys) prior to model ingestion. (0.01 USDC on Base L2) |
| synthetic_dataset_bias_auditorB | Audits synthetic agent training data distributions for demographic bias, representation skew, and label drift across sensitive attribute categories. (0.040 USDC on Base L2) |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Most tools target clearly distinct safety functions: PII masking, bias auditing, injection detection, injection neutralization, and secrets scanning. The two prompt-injection tools could be confused at a glance, but their descriptions distinguish detection/classification from stripping/neutralization.
All names use snake_case and are descriptive, but the structural pattern is mixed: some are verb-first (obfuscate_pii_entities, strip_prompt_injection) while others are noun phrases ending in auditor/classifier/scanner. This is readable but not a predictable convention.
Five tools is well within the sensible range for a focused AI safety/prompt shield server. Each tool covers a distinct guardrail capability, so none feels redundant or extraneous.
The surface covers key input-side guardrails: PII, bias, prompt injection detection/removal, and secrets scanning. Minor gaps remain around output-side moderation, toxicity classification, or policy enforcement, but the core lifecycle for a prompt safety server is reasonably covered.