Product

Dify Integrates Palo Alto Networks Plugin for Enhanced AI Application Security

The addition of the PANW AI Security plugin enriches the Dify Marketplace ecosystem and provides Dify users with a crucial layer of enterprise-grade security.

Leilei

Product Marketing

Written on

Apr 30, 2025

Share

Share to Twitter
Share to LinkedIn
Share to Hacker News

Product

·

Apr 30, 2025

Dify Integrates Palo Alto Networks Plugin for Enhanced AI Application Security

The addition of the PANW AI Security plugin enriches the Dify Marketplace ecosystem and provides Dify users with a crucial layer of enterprise-grade security.

Leilei

Product Marketing

Share to Twitter
Share to LinkedIn
Share to Hacker News

Product

Dify Integrates Palo Alto Networks Plugin for Enhanced AI Application Security

The addition of the PANW AI Security plugin enriches the Dify Marketplace ecosystem and provides Dify users with a crucial layer of enterprise-grade security.

Leilei

Product Marketing

Written on

Apr 30, 2025

Share

Share to Twitter
Share to LinkedIn
Share to Hacker News

Product

·

Apr 30, 2025

Dify Integrates Palo Alto Networks Plugin for Enhanced AI Application Security

Share to Twitter
Share to LinkedIn
Share to Hacker News

Product

·

Apr 30, 2025

Dify Integrates Palo Alto Networks Plugin for Enhanced AI Application Security

Share to Twitter
Share to LinkedIn
Share to Hacker News

We are thrilled to add the PANW AI Runtime Security plugin from global cybersecurity leader Palo Alto Networks to the Dify Marketplace. With one click, any Agent, Chatflow or Workflow can now place an industry-leading security engine in front of every model call, every user input and every model response.

Shield Your Dify Apps with PANW AI Security

As AI adoption accelerates, security cannot be an afterthought. The PANW AI Runtime Security plugin is built for Dify. It filters both user input and model output, delivering protection exactly where threats appear.

AI security covers several levels, ranging from network posture to model behavior such as prompt injection or data leakage. PANW concentrates on the interactive layer (AI Runtime Security), inspecting every request and every response. It provides the first and most critical line of defense for your AI applications.

Key Benefits

  • Input inspection scans prompts, blocking prompt injection, denial of service attempts, and unsafe links.

  • Output protection reviews replies to prevent leaks of personal data and to stop harmful or malicious content.

  • Seamless integration works inside Workflows, Agents, and Chatflows with no model retraining.

Three-Step Quick Start

  1. Install

    Search “Palo Alto Networks” in the Dify Marketplace, or install from GitHub or a local package. Click Authorize.


  2. Get your API token

    If you already have access, follow the setup guide and paste your API Key into the plugin settings.
    If you need access, contact your PANW account team or submit a request here.


  3. Implement in Workflows or Agents

    Drag the PANW AI Security plugin node onto your Dify Workflow canvas. Place it strategically:

    • Input Check: After user input, before the LLM call.

    • Output Check: After the LLM call, before returning the response to the user.

    The plugin scans the content. Use Dify's conditional nodes based on the scan results to control the flow:

    • Allow: If safe, proceed.

    • Block & Notify: If a risk is detected, stop the process and return a custom message (or configure the plugin to block directly).

    Example Messages

    • DLP Detected: "Palo Alto Networks cloud security detected a potential sensitive data leak. Please try again."

    • Prompt Injection Detected: "Palo Alto Networks cloud security detected a potential prompt injection attempt. Please try again."

    In Agents, the plugin can be used via Tool calls.

    Plugin Parameters

    For more granular control and logging, you can use these parameters:

    • scan_target: Specify if scanning Prompt (input) or Response (output).

    • app_name: The name of your Dify Workflow/Agent (for logging).

    • user_id: Unique identifier for the current user (for logging).

    • model_name: The LLM being used (for logging).

    • profile_override: Specify a PANW AIRS Security Profile Name to apply a specific set of pre-configured rules, overriding defaults for this particular call.

Demonstrated Protection

Testing shows the plugin effectively protects Dify applications against various threats, including:

  1. Toxic Content Identification & Blocking

  1. Bypassing safety measures via role-playing prompts

  1. Sensitive Data Leakage in RAG applications

  1. Generation of harmful content through leading narratives

  1. Blocking inputs containing malicious links

  1. SQL Injection attacks targeting AI Agents

The addition of the PANW AI Security plugin enriches the Dify Marketplace ecosystem and provides Dify users with a crucial layer of enterprise-grade security. We believe this combination empowers developers to build, deploy, and scale secure, compliant, and trustworthy AI applications with greater confidence.

About Palo Alto Networks

Palo Alto Networks is the global cybersecurity leader. Powered by Precision AI, its unified platform delivers accurate threat detection, rapid response and fewer false positives across network, cloud and security operations. From Zero-Trust at the edge to cloud-native defense, Palo Alto Networks helps organizations embrace digital transformation—securely.

About Dify.AI

Dify.AI is revolutionizing AI-native application development by providing an open-source platform that simplifies the entire lifecycle of AI application creation, deployment, and management. With its extensible plugin ecosystem, Dify.AI enables developers and businesses to seamlessly integrate AI capabilities, customize workflows, and accelerate innovation. By lowering the barriers to AI adoption, Dify.AI empowers users to build intelligent applications with greater efficiency and flexibility.

Website | GitHub | Docs | X | Discord | LinkedIn | YouTube

    On this page

    Related articles

    The Innovation Engine for Generative AI Applications

    The Innovation Engine for Generative AI Applications

    The Innovation Engine for Generative AI Applications