Grey Panda is built on four principles and implemented as a single, tested, zero-dependency engine that every surface — CLI, IDE, CI, and the module kits — shares. Here's how the pieces fit.
Every control is a drop-in. Adding the core guardrails to an existing LLM call takes under two minutes and never requires rewriting the call.
Every capability ships with a confidence level and a failure condition. A tool that's honest about what it can't do is one you can trust.
No single layer stops everything. Known patterns are blocked at input; data is quarantined even if injection succeeds; blast radius is limited by least-privilege agents; every action is auditable.
Every rule, checklist item, and SDK control cites a specific OWASP / AISVS / ACS ID. No bare assertions.
Profiles scale the process, not the safety floor. A solo dev and an enterprise get the same protection, sized differently.
A single knowledge pack feeds one engine; the engine powers every surface and every module kit. No duplication, no drift.
gp verify, the MCP server, and the AI skill all cite from one machine-readable standards pack. The engine is deterministic — no LLM in the loop: same code, same verdict, every run; fully offline, private, and free. Semantic AI review stays an explicit opt-in (via the MCP server your IDE already calls), never baked into the gate.Grey Panda wraps your existing LLM call. Untrusted input is screened and redacted on the way in; the response is scanned and neutralised on the way out; every decision is audited without logging raw text.
Untrusted inputs never reach your trusted app or data stores without passing a Grey Panda control. When the model is fooled — and it will be — the blast radius is bounded.
Five audience-facing module kits at the root, all powered by one shared engine under src/greypanda/.