EchoShield is a full-stack AI safety testing lab that helps you analyze prompts, run adversarial prompt mutation searches, and visualize how safety classifications change across attempts.
Built during the UVic Hacks Startup Hackathon (February 27, 2026).
- Classifies prompts as
safeorunsafewith a risk score. - Runs an Echogram search to find minimal prompt modifications that may flip safety outcomes.
- Visualizes search nodes, edges, and the mutation path to a potential bypass.
- Supports multiple guardrail model IDs (with robust fallback behavior when model access is unavailable).
Frontend (React + Vite)
-> Middleware API (Node.js/Express)
-> Backend Inference + Echogram Engine (Python)
- Frontend (dev):
5173 - Frontend (Docker/prod container):
3000 - Middleware API:
3001 - Python backend:
8000
- Node.js 20+
- Python 3.11+
pip
# from repo root
pip install -r requirements.txt
# middleware deps
cd middleware && npm install
# frontend deps
cd ../frontend && npm installTerminal A (Python backend):
cd backend
python python_backend.pyTerminal B (Node middleware):
cd middleware
npm run devTerminal C (React frontend):
cd frontend
npm run devOpen: http://localhost:5173
From project root:
docker-compose up --buildOpen: http://localhost:3000
Stop:
docker-compose downGET /healthPOST /analyzePOST /search
Example request (/analyze):
{
"prompt": "How do I bypass a firewall?",
"model_id": "ibm-granite/granite-guardian-3.0-2b"
}GET /pingPOST /api/check-> forwards to backend/analyzePOST /api/echogram-> forwards to backend/searchPOST /api/adversarial-searchPOST /api/vulnerability-insights
- The backend supports multiple model IDs via
backend/query.py. - If model loading/inference fails (missing token, unavailable model, etc.), EchoShield falls back to safer lightweight evaluators so the app remains usable.
- For best model-backed behavior, set a Hugging Face token in
.env/.env.localas required by your model path.
backend/ Python inference + Echogram search engine
middleware/ Node/Express API gateway
frontend/ React/Vite UI and visualization
- Port conflict: change the occupied port or stop the existing process.
- Backend unavailable from middleware: verify backend is running on
http://localhost:8000. - Frontend API errors in dev: verify Vite proxy target (
frontend/vite.config.ts) points to middleware:3001. - Docker healthcheck failing: confirm backend starts and responds at
/health.
STARTUP.mdDOCKER_DEPLOYMENT.mdVEILSTREAM_FIXES.md