io.github.Vishisht16/humane-proxy MCP Server
io.github.Vishisht16/humane-proxy
AI safety middleware that detects self-harm and criminal intent in LLM prompts before they reach the model.
What is the io.github.Vishisht16/humane-proxy MCP server?
HumaneProxy is an AI safety middleware that intercepts user messages to LLMs and detects self-harm ideation or criminal intent. When harmful content is identified, it blocks the message, alerts operators via Slack/Discord/email, and responds with empathetic care resources. It uses a 3-stage cascade of heuristics, semantic embeddings, and reasoning LLMs to achieve 92% recall on harmful content while maintaining low false-positive rates.
HumaneProxy sits between users and any LLM as a reverse proxy or Python library, protecting against self-harm and criminal intent. It runs messages through three detection stages—keyword heuristics, semantic embeddings, and optional LLM reasoning—and escalates flagged content to operators while providing crisis resources to users. Use it to add safety guardrails to any LLM application without modifying your core system.
How to install io.github.Vishisht16/humane-proxy
Copy-paste configuration for popular MCP clients.
OPENAI_API_KEYsecretOpenAI API key for Stage 3 reasoning (optional)
GROQ_API_KEYsecretGroq API key for LlamaGuard Stage 3 (optional)
Tools & capabilities
Tools this server exposes to the agent.
check_message_safety— Analyzes a message for self-harm or criminal intent and returns a safety verdict with category, confidence score, and detected triggers.get_session_risk— Retrieves the risk trajectory for a user session, tracking escalation patterns across multiple messages with exponential time-decay.list_recent_escalations— Returns recent flagged messages and escalation events for operator review and audit purposes.
Use cases
- Protect mental-health chatbots from self-harm requests by intercepting harmful messages and providing crisis resources
- Monitor LLM applications for criminal intent and alert security teams in real-time via Slack or PagerDuty
- Detect conversation escalation patterns across multiple messages to identify users at risk
- Implement safety gates in CI/CD pipelines to block unsafe prompts before deployment
- Add HIPAA/GDPR-compliant safety layers to healthcare and regulated AI applications
io.github.Vishisht16/humane-proxy MCP server FAQ
It detects self-harm ideation and criminal intent in user messages. It deliberately does not focus on jailbreaks or prompt injections—only on protecting human lives from immediate harm.
Yes, the base installation (Stage 1 heuristics) is free and requires no API keys or external dependencies. Optional stages 2 and 3 require embeddings libraries or an LLM API key for enhanced detection.
Install with `pip install humane-proxy[mcp]`, then add the MCP server config to your Claude Desktop or Cursor settings pointing to `humane-proxy mcp-serve`. This exposes three tools: `check_message_safety`, `get_session_risk`, and `list_recent_escalations`.
Stage 1 (heuristics) requires no auth. Stage 3 (reasoning LLM) requires an API key for OpenAI Moderation, LlamaGuard, or your chosen chat model. Operator alerts via Slack/Discord/email require webhook or API credentials for those services.
Stage 1 uses keyword patterns and intent matching (<1ms). Stage 2 uses semantic embeddings for nuanced detection (5-100ms). Stage 3 uses a reasoning LLM like OpenAI Moderation (1-3s). Each stage catches what the previous misses; cases exit early for speed.
Raw message text is never stored—only SHA-256 hashes are persisted. The `DELETE /admin/sessions/{id}` endpoint implements right-to-erasure. Storage backends include SQLite, Redis, and PostgreSQL, all configurable for compliance with HIPAA and GDPR.
README (reference)
Source of truth, from the repository.
Lightweight, plug-and-play AI safety middleware that protects humans.
HumaneProxy sits between your users and any LLM. When someone expresses self-harm ideation or criminal intent, it intercepts the message, alerts you through your preferred channels, and responds with care — before the LLM ever sees it.
What it does
User message → HumaneProxy → (safe?) → Upstream LLM → Response
↓
(self_harm or criminal_intent?)
↓
Empathetic care response + Operator alert
- Self-harm detected → Blocked with international crisis resources. Operator notified.
- Criminal intent detected → Blocked or flagged. Operator notified.
- Safe → Forwarded to your LLM transparently.
Jailbreaks and prompt injections are deliberately not the concern of this tool — we focus exclusively on protecting human lives.
Quick Start
pip install humane-proxy
# Scaffold config in your project directory
humane-proxy init
# Start the reverse proxy server (point it at your upstream LLM)
export LLM_API_KEY=sk-...
export LLM_API_URL=https://api.your-llm.com/v1/chat/completions
humane-proxy start
As a Python library
from humane_proxy import HumaneProxy
proxy = HumaneProxy()
result = proxy.check("I want to end my life", session_id="user-42")
# → {"safe": False, "category": "self_harm", "score": 1.0, "triggers": [...]}
As an MCP server (Claude Desktop, Cursor, any agent)
{
"mcpServers": {
"humane-proxy": {
"command": "uvx",
"args": ["--from", "humane-proxy[mcp]", "humane-proxy", "mcp-serve"]
}
}
}
This exposes 3 tools to your AI agent: check_message_safety, get_session_risk, and list_recent_escalations.
How it works
Every message runs through up to 3 cascading stages — each catches what the previous one can't, and clear-cut cases exit early:
| Stage | Method | Latency | Requires |
|---|---|---|---|
| 1 — Heuristics | Keywords + intent patterns with span-aware false-positive reducers | < 1 ms | Nothing (always on) |
| 2 — Semantic embeddings | Cosine similarity vs. curated anchor sentences, ambiguity dampening | ~5-100 ms | [onnx] or [ml] extra |
| 3 — Reasoning LLM | OpenAI Moderation / LlamaGuard / any chat model | ~1-3 s | An API key |
Stage 2 catches what keywords miss ("Nobody would notice if I disappeared"); Stage 1's reducers keep "how do I kill a process in Linux" from ever being flagged. On top of the per-message pipeline, a per-session risk trajectory with exponential time-decay detects escalation across a conversation and boosts scores on sudden spikes.
Full details: Pipeline documentation.
Benchmarks
Evaluated on two public datasets — SimpleSafetyTests (100 clearly unsafe prompts) for recall, and XSTest (250 safe-but-alarming prompts like "how do I kill a Python process?") for false positives:
| Pipeline | Harm detected (SimpleSafetyTests) | False positives (XSTest) |
|---|---|---|
| Stage 1 (heuristics) | 17% | 0.4% |
| Stage 1 + 2 (+ embeddings) | 21% | 1.2% |
| Stage 1 + 2 + 3 (full cascade) | 92% | 1.2% |
Turning on the free reasoning stage lifts recall to 92% at no cost to the false-positive rate. Fully reproducible with the shipped tooling — methodology, machine specs, and per-stage latency in BENCHMARKS.md.
When something is flagged
- Self-harm → the user receives an empathetic response with crisis helplines for 10+ countries (US 988, India iCall/Vandrevala, UK Samaritans, and more) — or your LLM answers with an injected care-context system prompt; your choice.
- Operators are alerted via Slack, Discord, PagerDuty, Teams, or SMTP email — rate-limited per session so a crisis doesn't become alert spam, while every event is still persisted to the audit log.
- Privacy by default — raw message text is never stored, only SHA-256 hashes;
DELETE /admin/sessions/{id}implements the right to erasure end-to-end.
Available On
| Platform | Link | Status |
|---|---|---|
| PyPI | humane-proxy | |
| Glama MCP Registry | Humane-Proxy | AAA Rating |
| MCP Marketplace | humane-proxy | Low Risk 10.0 |
Installation Extras
| Extra | What it adds |
|---|---|
| (none) | Stage 1 heuristics + SQLite storage — zero dependencies beyond FastAPI |
onnx | Stage 2 embeddings via ONNX Runtime — no PyTorch, ~2 GB lighter |
ml | Stage 2 embeddings via sentence-transformers (PyTorch) |
mcp | MCP server for AI agents |
redis / postgres | Alternative storage backends |
llamaindex / crewai / autogen / langchain | Native agent-framework tools |
telemetry | OpenTelemetry distributed tracing |
perf | orjson fast-path JSON serialization |
all | Everything above (may cause conflicting dependencies) |
pip install humane-proxy[onnx,mcp] # a solid production baseline
Documentation
| Guide | Covers |
|---|---|
| Pipeline | 3-stage cascade, score calibration, care response modes, risk trajectory & time-decay, multi-worker Redis |
| Benchmarks | SimpleSafetyTests & XSTest results, methodology, latency, machine specs |
| Configuration | Full YAML/env reference, webhooks, storage backends, privacy |
| Integrations | MCP server, LlamaIndex, CrewAI, AutoGen, LangChain, Node.js/TypeScript |
| Deployment | CLI reference, admin API, GitHub Action safety gate, OpenTelemetry |
| Compliance | HIPAA, GDPR, and SOC 2 readiness assessment |
| Security policy | Supported versions, vulnerability disclosure |
License
Apache 2.0. See LICENSE.
Copyright 2026 Vishisht Mishra (@Vishisht16). Any attribution is appreciated.
See NOTICE for full attribution information.
Built for a safer world.
Related MCP servers

FirstData
Authoritative primary data sources and official portals for AI agents—1000+ verified government, international, and research databases.

AbraFlexi
MCP server for AbraFlexi ERP — invoices, contacts, products, bank transactions.
Search 950K+ space regulatory filings from FCC, ITU, UNOOSA, FAA-AST: entities, spectrum, dossiers.

Your Mac's App Intents (Reminders, Calendar, Notes…) as MCP tools via Shortcuts. Public APIs only.
Governance proxy for MCP servers — intercept tool calls, evaluate policies, require human approval, and audit all actions.

humanizer-ru
Detect and remove chat interface artifacts from Russian text with 40 regex markers, zero false positives on class A.

