Unsigned
62
4
agentguard-default-guardrails
:Byshoubhik
Use the Pull Tag button to download this ModelKit.
Or, read our KitOps documentation to learn how to use kit unpack --filter to download only the components you need.
Package
- Name
- agentguard-default-guardrails
- Version
- 4.0.0
- Authors
- jozu-ai
- Description
- The guardrail policy a standalone AgentGuard install starts with.
Identical to :v2 in every rule and every action. The only change is
direction: all seven documents are now input, where :v2 carried
direction: both on five of them.
That is a cost change, not a coverage change. A "both" document is
evaluated twice per exchange, once on the prompt and again on the model's
response, and the response is the larger of the two. On a 150KB body the
output pass costs about 77ms per request and sees nothing the input pass
did not, because the sensitive content originates in the prompt. Removing
it roughly halves evaluation work per exchange; measured detection on the
input direction is identical to :v2.
Actions, unchanged from :v2 and mostly blocking: Enforce on
01-credential-leakage, 02-government-identity, 03-financial-identifiers,
04-indirect-prompt-injection and the dormant 05-scanner-thresholds; Redact
on z1-contact-and-demographic-detail; Audit on 00-internal-material-egress.
So a credential, a Social Security number, a payment card, a government
identity number or attachment-borne prompt injection refuses the request,
while a date of birth or contact detail is masked and the request
proceeds. If you want a mostly-masking posture instead, that is :v3.
Background: :v2 inherited direction: both from the AgentGuard reference
bundle, where it is documented as a backup for the input-side rules. The
shipped default before it was input-only, and on a host gateway carrying a
long conversation the doubled work is not worth a backup that cannot see
anything new.
Guardrails only. Must remain anonymously pullable.