azure-ai-contentsafety-py
microsoft/agent-skills/.github/plugins/azure-sdk-python/skills/azure-ai-contentsafety-py/SKILL.md
Azure AI Content Safety SDK for Python. Use for detecting harmful content in text and images with multi-severity classification. Triggers: "azure-ai-contentsafety", "ContentSafetyClient", "content moderation", "harmful content", "text analysis", "image analysis".
Skill3.1k starsChanged 8 months ago
- Installs packages
What's in it
- Azure AI Content Safety SDK for Python
- Installation
- Environment Variables
- Authentication & Lifecycle
- Legacy: API Key (existing keyed deployments)
- Analyze Text
- Analyze Image
- Image from URL
- Text Blocklist Management
- Create Blocklist
- Add Block Items
- Analyze with Blocklist
- Severity Levels
- Harm Categories
- Severity Scale
- Client Types
- Best Practices
- Reference Files
---
name: azure-ai-contentsafety-py
description: |
Azure AI Content Safety SDK for Python. Use for detecting harmful content in text and images with multi-severity classification.
Triggers: "azure-ai-contentsafety", "ContentSafetyClient", "content moderation", "harmful content", "text analysis", "image analysis".
license: MIT
metadata:
author: Microsoft
version: "1.0.0"
package: azure-ai-contentsafety
---
# Azure AI Content Safety SDK for Python
Detect harmful user-generated and AI-generated content in applications.
## Installation
```bash
pip install azure-ai-contentsafety
```
## Environment Variables
```bash
CONTENT_SAFETY_ENDPOINT=https://<resource>.cognitiveservices.azure.com # Required for all auth methods
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production
CONTENT_SAFETY_KEY=<your-api-key> # Only required for the legacy API-key auth path below
```
## Authentication & Lifecycle
> **🔑 Two rules apply to every code sample below:**
>
> 1. **Prefer `DefaultAzureCredential`.** It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
> - Local dev: `DefaultAzureCredential` works as-is.
> - Production: set `AZURE_TOKEN_CREDENTIALS=prod` (or `AZURE_TOKEN_CREDENTIALS=<specific_credential>`) to constrain the credential chain to production-safe credentials.
> 2. **Wrap every client in a context manager** so HTTP transports, sockets, and token caches are released deterministically:
> - Sync: `with <Client>(...) as client:`
> - Async: `async with <Client>(...) as client:` **and** `async with DefaultAzureCredential() as credential:` (from `azure.identity.aio`)
>
> Snippets may abbreviate this setup, but production code should always follow both rules.
```python
import os
from azure.identity import DefaultAzureCredential, ManagedIdentityCredential
from azure.ai.contentsafety import ContentSafetyClient
from azure.ai.contentsafety.models import AnalyzeTextOptions
# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
credential = DefaultAzureCredential(require_envvar=True)
# Or use a specific credential directly in production:
# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes
# credential = ManagedIdentityCredential()
with ContentSafetyClient(
endpoint=os.environ["CONTENT_SAFETY_ENDPOINT"],
credential=credential,
) as client:
response = client.analyze_text(AnalyzeTextOptions(text="Hello, world!"))
```
### Legacy: API Key (existing keyed deployments)
New code should use `DefaultAzureCredential` above. Use `AzureKeyCredential` only if you have an existing keyed deployment that hasn't been migrated to Entra ID yet — for example, regulated environments still completing their Entra rollout.
```python
import os
from azure.core.credentials import AzureKeyCredential
from azure.ai.contentsafety import ContentSafetyClient
from azure.ai.contentsafety.models import AnalyzeTextOptions
with ContentSafetyClient(
endpoint=os.environ["CONTENT_SAFETY_ENDPOINT"],
credential=AzureKeyCredential(os.environ["CONTENT_SAFETY_KEY"]),
) as client:
response = client.analyze_text(AnalyzeTextOptions(text="Hello, world!"))
```
The `BlocklistClient` accepts the same `AzureKeyCredential` if you also need to manage blocklists with a key.
## Analyze Text
```python
from azure.ai.contentsafety import ContentSafetyClient
from azure.ai.contentsafety.models import AnalyzeTextOptions, TextCategory
from azure.identity import DefaultAzureCredential
with ContentSafetyClient(endpoint, DefaultAzureCredential()) as client:
request = AnalyzeTextOptions(text="Your text content to analyze")
response = client.analyze_text(request)
# Check each category
for category in [TextCategory.HATE, TextCategory.SELF_HARM,
TextCategory.SEXUAL, TextCategory.VIOLENCE]:
result = next((r for r in response.categories_analysis
if r.category == category), None)
if result:
print(f"{category}: severity {result.severity}")
```
## Analyze Image
```python
from azure.ai.contentsafety import ContentSafetyClient
from azure.ai.contentsafety.models import AnalyzeImageOptions, ImageData
from azure.identity import DefaultAzureCredential
import base64
with ContentSafetyClient(endpoint, DefaultAzureCredential()) as client:
# From file
with open("image.jpg", "rb") as f:
image_data = base64.b64encode(f.read()).decode("utf-8")
request = AnalyzeImageOptions(
image=ImageData(content=image_data)
)
response = client.analyze_image(request)
for result in response.categories_analysis:
print(f"{result.category}: severity {result.severity}")
```
### Image from URL
```python
from azure.ai.contentsafety.models import AnalyzeImageOptions, ImageData
request = AnalyzeImageOptions(
image=ImageData(blob_url="https://example.com/image.jpg")
)
response = client.analyze_image(request)
```
## Text Blocklist Management
### Create Blocklist
```python
from azure.ai.contentsafety import BlocklistClient
from azure.ai.contentsafety.models import TextBlocklist
from azure.identity import DefaultAzureCredential
with BlocklistClient(endpoint, DefaultAzureCredential()) as blocklist_client:
blocklist = TextBlocklist(
blocklist_name="my-blocklist",
description="Custom terms to block"
)
result = blocklist_client.create_or_update_text_blocklist(
blocklist_name="my-blocklist",
options=blocklist
)
```
### Add Block Items
```python
from azure.ai.contentsafety.models import AddOrUpdateTextBlocklistItemsOptions, TextBlocklistItem
items = AddOrUpdateTextBlocklistItemsOptions(
blocklist_items=[
TextBlocklistItem(text="blocked-term-1"),
TextBlocklistItem(text="blocked-term-2")
]
)
result = blocklist_client.add_or_update_blocklist_items(
blocklist_name="my-blocklist",
options=items
)
```
### Analyze with Blocklist
```python
from azure.ai.contentsafety.models import AnalyzeTextOptions
request = AnalyzeTextOptions(
text="Text containing blocked-term-1",
blocklist_names=["my-blocklist"],
halt_on_blocklist_hit=True
)
response = client.analyze_text(request)
if response.blocklists_match:
for match in response.blocklists_match:
print(f"Blocked: {match.blocklist_item_text}")
```
## Severity Levels
Text analysis returns 4 severity levels (0, 2, 4, 6) by default. For 8 levels (0-7):
```python
from azure.ai.contentsafety.models import AnalyzeTextOptions, AnalyzeTextOutputType
request = AnalyzeTextOptions(
text="Your text",
output_type=AnalyzeTextOutputType.EIGHT_SEVERITY_LEVELS
)
```
## Harm Categories
| Category | Description |
|----------|-------------|
| `Hate` | Attacks based on identity (race, religion, gender, etc.) |
| `Sexual` | Sexual content, relationships, anatomy |
| `Violence` | Physical harm, weapons, injury |
| `SelfHarm` | Self-injury, suicide, eating disorders |
## Severity Scale
| Level | Text Range | Image Range | Meaning |
|-------|------------|-------------|---------|
| 0 | Safe | Safe | No harmful content |
| 2 | Low | Low | Mild references |
| 4 | Medium | Medium | Moderate content |
| 6 | High | High | Severe content |
## Client Types
| Client | Purpose |
|--------|---------|
| `ContentSafetyClient` | Analyze text and images |
| `BlocklistClient` | Manage custom blocklists |
## Best Practices
1. **Pick sync OR async and stay consistent.** Do not mix `azure.ai.contentsafety` sync clients with `azure.ai.contentsafety.aio` async clients in the same call path. Choose one mode per module.
2. **Always use context managers for clients and async credentials.** Wrap every client in `with ContentSafetyClient(...) as client:` (sync) or `async with ContentSafetyClient(...) as client:` (async). For async `DefaultAzureCredential` from `azure.identity.aio`, also use `async with credential:` so tokens and transports are cleaned up.
3. **Use blocklists** for domain-specific terms
4. **Set severity thresholds** appropriate for your use case
5. **Handle multiple categories** — content can be harmful in multiple ways
6. **Use halt_on_blocklist_hit** for immediate rejection
7. **Log analysis results** for audit and improvement
8. **Consider 8-severity mode** for finer-grained control
9. **Pre-moderate AI outputs** before showing to users
## Reference Files
| File | Contents |
|------|----------|
| [references/capabilities.md](references/capabilities.md) | Additional non-hero capabilities, operation-group coverage, and production checklists. |
| [references/non-hero-scenarios.md](references/non-hero-scenarios.md) | Dedicated non-hero examples for secondary/advanced scenarios. |
More agent context in microsoft/agent-skills
211 other files this repository gives its agents, the first 60 shown.
AGENTS.md
Copilot instructions
llms.txt
Skill
- cost-analysis.github/plugins/azure-cost/skills/cost-analysis/SKILL.md
- cost-estimation.github/plugins/azure-cost/skills/cost-estimation/SKILL.md
- cost-governance.github/plugins/azure-cost/skills/cost-governance/SKILL.md
- cost-optimization.github/plugins/azure-cost/skills/cost-optimization/SKILL.md
- azure-kusto-graph.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-graph/SKILL.md
- azure-kusto-irql-graph.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph/SKILL.md
- azure-kusto-irql.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql/SKILL.md
- azure-local-multi-rack.github/plugins/azure-local-skills/skills/azure-local-multi-rack/SKILL.md
- azure-local.github/plugins/azure-local-skills/skills/azure-local/SKILL.md
- azure-ai-agents-persistent-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-ai-agents-persistent-dotnet/SKILL.md
- azure-ai-document-intelligence-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-ai-document-intelligence-dotnet/SKILL.md
- azure-ai-openai-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-ai-openai-dotnet/SKILL.md
- azure-ai-projects-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-ai-projects-dotnet/SKILL.md
- azure-ai-voicelive-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-ai-voicelive-dotnet/SKILL.md
- azure-eventgrid-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-eventgrid-dotnet/SKILL.md
- azure-eventhub-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-eventhub-dotnet/SKILL.md
- azure-identity-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-identity-dotnet/SKILL.md
- azure-maps-search-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-maps-search-dotnet/SKILL.md
- azure-mgmt-apicenter-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-apicenter-dotnet/SKILL.md
- azure-mgmt-apimanagement-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-apimanagement-dotnet/SKILL.md
- azure-mgmt-applicationinsights-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-applicationinsights-dotnet/SKILL.md
- azure-mgmt-arizeaiobservabilityeval-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-arizeaiobservabilityeval-dotnet/SKILL.md
- azure-mgmt-botservice-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-botservice-dotnet/SKILL.md
- azure-mgmt-fabric-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-fabric-dotnet/SKILL.md
- azure-mgmt-mongodbatlas-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-mongodbatlas-dotnet/SKILL.md
- azure-mgmt-weightsandbiases-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-mgmt-weightsandbiases-dotnet/SKILL.md
- azure-resource-manager-cosmosdb-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-cosmosdb-dotnet/SKILL.md
- azure-resource-manager-durabletask-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-durabletask-dotnet/SKILL.md
- azure-resource-manager-mysql-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-mysql-dotnet/SKILL.md
- azure-resource-manager-playwright-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-playwright-dotnet/SKILL.md
- azure-resource-manager-postgresql-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-postgresql-dotnet/SKILL.md
- azure-resource-manager-redis-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-redis-dotnet/SKILL.md
- azure-resource-manager-sql-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-resource-manager-sql-dotnet/SKILL.md
- azure-search-documents-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-search-documents-dotnet/SKILL.md
- azure-security-keyvault-keys-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-security-keyvault-keys-dotnet/SKILL.md
- azure-servicebus-dotnet.github/plugins/azure-sdk-dotnet/skills/azure-servicebus-dotnet/SKILL.md
- m365-agents-dotnet.github/plugins/azure-sdk-dotnet/skills/m365-agents-dotnet/SKILL.md
- microsoft-azure-webjobs-extensions-authentication-events-dotnet.github/plugins/azure-sdk-dotnet/skills/microsoft-azure-webjobs-extensions-authentication-events-dotnet/SKILL.md
- azure-ai-agents-persistent-java.github/plugins/azure-sdk-java/skills/azure-ai-agents-persistent-java/SKILL.md
- azure-ai-anomalydetector-java.github/plugins/azure-sdk-java/skills/azure-ai-anomalydetector-java/SKILL.md
- azure-ai-contentsafety-java.github/plugins/azure-sdk-java/skills/azure-ai-contentsafety-java/SKILL.md
- azure-ai-formrecognizer-java.github/plugins/azure-sdk-java/skills/azure-ai-formrecognizer-java/SKILL.md
- azure-ai-projects-java.github/plugins/azure-sdk-java/skills/azure-ai-projects-java/SKILL.md
- azure-ai-vision-imageanalysis-java.github/plugins/azure-sdk-java/skills/azure-ai-vision-imageanalysis-java/SKILL.md
- azure-ai-voicelive-java.github/plugins/azure-sdk-java/skills/azure-ai-voicelive-java/SKILL.md
- azure-appconfiguration-java.github/plugins/azure-sdk-java/skills/azure-appconfiguration-java/SKILL.md
- azure-communication-callautomation-java.github/plugins/azure-sdk-java/skills/azure-communication-callautomation-java/SKILL.md
- azure-communication-callingserver-java.github/plugins/azure-sdk-java/skills/azure-communication-callingserver-java/SKILL.md
- azure-communication-chat-java.github/plugins/azure-sdk-java/skills/azure-communication-chat-java/SKILL.md
- azure-communication-common-java.github/plugins/azure-sdk-java/skills/azure-communication-common-java/SKILL.md
- azure-communication-sms-java.github/plugins/azure-sdk-java/skills/azure-communication-sms-java/SKILL.md
- azure-compute-batch-java.github/plugins/azure-sdk-java/skills/azure-compute-batch-java/SKILL.md
- azure-cosmos-java.github/plugins/azure-sdk-java/skills/azure-cosmos-java/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool registry_write, action report. How to connect one.

