feat: add support MCP guardrail to noma

This commit is contained in:
Yuta Saito 2026-01-05 11:42:02 +09:00
parent 7937c8674b
commit 4eecf59f86
3 changed files with 12 additions and 6 deletions

View file

@ -85,4 +85,5 @@ MCP guardrails work with all LiteLLM-supported guardrail providers:
- **Bedrock**: AWS Bedrock guardrails
- **Lakera**: Content moderation
- **Aporia**: Custom guardrails
- **Noma**: Noma Security
- **Custom**: Your own guardrail implementations

View file

@ -39,6 +39,8 @@ guardrails:
- `pre_call` Run **before** LLM call, on **input**
- `post_call` Run **after** LLM call, on **input & output**
- `during_call` Run **during** LLM call, on **input**. Same as `pre_call` but runs in parallel with the LLM call. Response not returned until guardrail check completes
- `pre_mcp_call`: Scan MCP tool call inputs before execution
- `during_mcp_call`: Monitor MCP tool calls in real-time
### 2. Start LiteLLM Gateway

View file

@ -41,6 +41,7 @@ from litellm.main import stream_chunk_builder
from litellm.proxy._types import UserAPIKeyAuth
from litellm.types.guardrails import GuardrailEventHooks
from litellm.types.utils import (
CallTypes,
CallTypesLiteral,
EmbeddingResponse,
GuardrailStatus,
@ -582,12 +583,11 @@ class NomaGuardrail(CustomGuardrail):
) -> Optional[Union[Exception, str, dict]]:
verbose_proxy_logger.debug("Running Noma pre-call hook")
if (
self.should_run_guardrail(
data=data, event_type=GuardrailEventHooks.pre_call
)
is False
):
event_type = GuardrailEventHooks.pre_call
if call_type == CallTypes.call_mcp_tool.value:
event_type = GuardrailEventHooks.pre_mcp_call
if self.should_run_guardrail(data=data, event_type=event_type) is False:
return data
# In monitor mode, run Noma check in background and return immediately
@ -638,6 +638,9 @@ class NomaGuardrail(CustomGuardrail):
call_type: CallTypesLiteral,
) -> Union[Exception, str, dict, None]:
event_type: GuardrailEventHooks = GuardrailEventHooks.during_call
if call_type == CallTypes.during_mcp_call.value:
event_type = GuardrailEventHooks.pre_mcp_call
if self.should_run_guardrail(data=data, event_type=event_type) is not True:
return data