🚀 Prompt-Recon (v2.0)
Prompt-Recon v2.0 is a comprehensive lifecycle AI asset defense and auditing system.
This tool is designed for security researchers, red-teamers, and DevSecOps teams to audit, intercept, and fix hardcoded "system prompt leaks" and other confidential data vulnerabilities within codebases and runtime traffic.
Core Features (v2.0)
- 🛡️ Runtime Dynamic Gateway (Sentinel Proxy): An ASGI network proxy that intercepts LLM-bound traffic (e.g., OpenAI, Claude) to detect and block prompt leaks at runtime.
- 🧠 Embedding Vector Analysis: Integrates embedding models like
bge-small-zhto detect obfuscated prompts via vector space similarity, complementing pure regex scanning. - ⚖️ LLM Sandbox Validation: Implements LangChain-based validation loops, using LLMs to evaluate suspected leaked prompts and lower false-positive rates.
- 🕸️ AST/CPG Data Flow Tracking: Tracks variables and function calls at the Python Abstract Syntax Tree (AST) level to reconstruct fragmented prompt strings.
- 👥 Git Security Auditing: Uses
GitPythonto extract commit history features associated with leaked code, assisting in engineering risk alerts. - 💧 Zero-Width Watermarking: Uses invisible zero-width characters to watermark core prompts to help track insider threats.
- 🤖 Auto-Remediation: Can automatically refactor detected hard-coded prompts using
os.environlookups and safely extract the secrets to an.env.remediatedfile. - ⌨️ Multi-Mode CLI: Provides
scan,patch, andsentinelas the three core operational modes.
Installation
Clone this repository:
git clone https://github.com/Ha1baraA11/Prompt-Recon.git cd prompt-recon(Recommended) Create a virtual environment:
python3 -m venv venv source venv/bin/activateInstall dependencies and the tool in "editable" mode:
# Install the core dependencies pip install rich gitpython # Install the tool pip install -e .
Usage
Once installed, the promptrecon command will be available.
# Scan a local directory
promptrecon -d /path/to/your/codebase
# Scan a public GitHub repository (will be cloned automatically)
promptrecon -u [https://github.com/user/vulnerable-repo](https://github.com/user/vulnerable-repo)
# Generate multiple reports
promptrecon -d . --md report.md --csv report.csv --jsonl results.jsonl
# Run in --safe mode (skips official repos)
promptrecon -u [https://github.com/openai/gpt-3](https://github.com/openai/gpt-3) --safe
# Use in CI/CD (will exit with code 3 if critical risk found)
promptrecon -d .