You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The guard checks known injection phrases, then embeds each intent description and the input, computes cosine similarity, and compares the highest score with intent.semantic.threshold (default 0.7).
models.extractor controls both preloading and runtime analysis. Custom models must support the Transformers.js feature-extraction pipeline with mean pooling and normalized embeddings.
All entries in semantic.intents participate in scoring. allowedIntent and mode remain accepted for compatibility; they do not select a separate enforcement path. List only the intent descriptions you want to allow. Tune thresholds against representative allowed and disallowed prompts.
Injection patterns are checked across all message parts, history and documents, not just the first text part. Trusted history or documents can also match a pattern. Semantic scoring uses the prompt or all parts of the final message. These checks are heuristic and do not guarantee protection against prompt injection.