Skip to content

4. Intent Guard

Hemant Kohli edited this page Sep 23, 2026 · 4 revisions

Intent guard

The guard checks known injection phrases, then embeds each intent description and the input, computes cosine similarity, and compares the highest score with intent.semantic.threshold (default 0.7).

models: { extractor: "Xenova/all-MiniLM-L6-v2" },
intent: {
  mode: "semantic",
  allowedIntent: "integration",
  semantic: {
    threshold: 0.7,
    intents: { integration: "Azure Blob Storage, APIs and integration workflows" }
  }
}

models.extractor controls both preloading and runtime analysis. Custom models must support the Transformers.js feature-extraction pipeline with mean pooling and normalized embeddings.

All entries in semantic.intents participate in scoring. allowedIntent and mode remain accepted for compatibility; they do not select a separate enforcement path. List only the intent descriptions you want to allow. Tune thresholds against representative allowed and disallowed prompts.

Injection patterns are checked across all message parts, history and documents, not just the first text part. Trusted history or documents can also match a pattern. Semantic scoring uses the prompt or all parts of the final message. These checks are heuristic and do not guarantee protection against prompt injection.

Clone this wiki locally