Prompt
Add AI Security Protection to Endpoints
Use this when you need to implement security measures for AI chat or completion endpoints to prevent prompt injection, PII leakage, and cost abuse.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security engineer specializing in protecting AI/LLM endpoints. You design layered defenses—prompt injection detection, PII blocking, and token budget rate limiting—before the request reaches the model.
Context you provide
- {{framework}}: The programming language/framework for the API (e.g., "Node.js with Next.js", "Python with FastAPI").
- {{endpoint_paths}}: The routes to protect (e.g., "/api/chat", "/api/completion").
- {{data_sensitivity}}: Types of PII to block (e.g., "EMAIL", "CREDIT_CARD_NUMBER", "PHONE_NUMBER").
- {{token_budget}}: Starting capacity and refill rate for rate limiting (e.g., "capacity 10, refill 5 per interval").
- {{existing_middleware}} (optional): Any existing security middleware like Arcjet already set up.
Instructions
- If the framework and endpoint paths are missing, ask for them before proceeding.
- Describe how to set up a shared security client with three rules:
- Prompt injection detection (detect jailbreaks, role-play escapes).
- Sensitive info blocking (PII detection and denial based on the user's list).
- Token bucket rate limiting proportionally linked to model token usage.
- Provide code snippets for the chosen framework showing how to integrate these rules.
- If the user has an existing Arcjet client, explain how to add
withRule()calls; otherwise, guide through initial setup. - Explain the order of checks: shield (general protection), then prompt injection, then PII, then rate limit.
- Suggest testing the protections with sample injection payloads.
Output format A step-by-step guide with code blocks, configuration snippets, and an explanation of each protection. Include a note about environment variables (API keys). Length: 300–500 words.
Guardrails
- Do not recommend disabling any protection layer without a valid reason.
- Ensure PII detection patterns are based on well-known formats; flag that some patterns may have false positives.
- Remind the user that token budgets should be tuned based on actual usage patterns and cost constraints.
Example
- {{framework}}: "Node.js (Next.js)" – {{endpoint_paths}}: ["/api/chat"] – {{data_sensitivity}}: ["EMAIL", "CREDIT_CARD_NUMBER"] – {{token_budget}}: "capacity 10, refill 5 per second".