Repository navigation
12. Security and Operational Errors
Injection checks cover all message parts, history and documents. Semantic intent uses the prompt or all parts of the final message. These heuristic checks can miss attacks and block benign content, including trusted history. They do not replace application authorization.
PII tokens use cryptographic namespaces. Masking handles longer overlapping values first, ignores empty matches, and caches tokens only after successful vault writes. Tokenizer state is kept outside user-provided context fields. Guard-generated metadata omits prompt copies and classifier output; application metadata and requests can still contain sensitive data.
Vault scopes and opaque tokens are not tenant authorization controls. Cross-turn lookup can recover tokens across scopes in the same backend. Isolate adapters or Redis prefixes and token indexes across trust boundaries. Retention, encryption, request deadlines and durable approvals remain application responsibilities.
| Failure | Public result |
|---|---|
| Model policy rejection | Hook returns finishReason: "blocked"; Genkit generation raises FAILED_PRECONDITION with that response in its details |
| Tool policy rejection |
GuardToolError with its decision |
| Guard model loading/inference |
GuardModelError, code MODEL_UNAVAILABLE, with or without a fallback |
| Audit store/callback delivery |
GuardOperationalError, code AUDIT_UNAVAILABLE
|
| Vault access through tokenizer/middleware |
GuardOperationalError, code VAULT_UNAVAILABLE
|
| Provider/tool implementation | Original downstream error |
Branch on class/code instead of infrastructure messages. Guard-owned failures omit original messages and causes because they can contain PII. Direct storage adapter calls retain adapter errors; configuration validation errors remain configuration errors. Approval-callback failures produce a tool-policy error, not an audit-delivery error.
Required checks fail closed before downstream execution. Explicit local model fallback runs once; audit failures never trigger model fallback. There is no automatic audit or tool retry.
Store append precedes the decision callback. A callback failure cannot undo an already saved decision. Restoration or response scanning can fail after a model or tool has run. No rollback occurs; retrying a side-effecting tool can duplicate its effects.
This changes the earlier no-fallback behavior: model exceptions are now sanitized even when no fallback is configured. Update consumers that inspect underlying error messages or causes. See 10.-Decision-Storage-and-Model-Fallback for model selection and persistent delivery.
The v0.2.0 local audit after compatible dependency updates reports no production-only findings. The full graph still reports 49 moderate and 7 high findings in Genkit's transitive dependencies, including OpenTelemetry and UUID. Genkit is a development dependency here and a required peer in consuming applications, so audit the complete application graph. The suggested forced remediation would downgrade Genkit incompatibly; no forced downgrade or unverified override was applied. Audit results are a preparation-time snapshot, not a permanent guarantee.
See 11.-Framework-Compatibility for test coverage and 1.-Home for the v1.0.0-rc.1 API-freeze milestone.