Skip to content

12. Security and Operational Errors

Hemant Kohli edited this page Sep 23, 2026 · 1 revision

Security and operational errors

Security boundaries

Injection checks cover all message parts, history and documents. Semantic intent uses the prompt or all parts of the final message. These heuristic checks can miss attacks and block benign content, including trusted history. They do not replace application authorization.

PII tokens use cryptographic namespaces. Masking handles longer overlapping values first, ignores empty matches, and caches tokens only after successful vault writes. Tokenizer state is kept outside user-provided context fields. Guard-generated metadata omits prompt copies and classifier output; application metadata and requests can still contain sensitive data.

Vault scopes and opaque tokens are not tenant authorization controls. Cross-turn lookup can recover tokens across scopes in the same backend. Isolate adapters or Redis prefixes and token indexes across trust boundaries. Retention, encryption, request deadlines and durable approvals remain application responsibilities.

Error contract

Failure Public result
Model policy rejection Hook returns finishReason: "blocked"; Genkit generation raises FAILED_PRECONDITION with that response in its details
Tool policy rejection GuardToolError with its decision
Guard model loading/inference GuardModelError, code MODEL_UNAVAILABLE, with or without a fallback
Audit store/callback delivery GuardOperationalError, code AUDIT_UNAVAILABLE
Vault access through tokenizer/middleware GuardOperationalError, code VAULT_UNAVAILABLE
Provider/tool implementation Original downstream error

Branch on class/code instead of infrastructure messages. Guard-owned failures omit original messages and causes because they can contain PII. Direct storage adapter calls retain adapter errors; configuration validation errors remain configuration errors. Approval-callback failures produce a tool-policy error, not an audit-delivery error.

Failure ordering and retries

Required checks fail closed before downstream execution. Explicit local model fallback runs once; audit failures never trigger model fallback. There is no automatic audit or tool retry.

Store append precedes the decision callback. A callback failure cannot undo an already saved decision. Restoration or response scanning can fail after a model or tool has run. No rollback occurs; retrying a side-effecting tool can duplicate its effects.

This changes the earlier no-fallback behavior: model exceptions are now sanitized even when no fallback is configured. Update consumers that inspect underlying error messages or causes. See 10.-Decision-Storage-and-Model-Fallback for model selection and persistent delivery.

Dependency audit

The v0.2.0 local audit after compatible dependency updates reports no production-only findings. The full graph still reports 49 moderate and 7 high findings in Genkit's transitive dependencies, including OpenTelemetry and UUID. Genkit is a development dependency here and a required peer in consuming applications, so audit the complete application graph. The suggested forced remediation would downgrade Genkit incompatibly; no forced downgrade or unverified override was applied. Audit results are a preparation-time snapshot, not a permanent guarantee.

See 11.-Framework-Compatibility for test coverage and 1.-Home for the v1.0.0-rc.1 API-freeze milestone.

Clone this wiki locally