Injection Detection & Response
ivy.agent.prompt-injection-guard · v1.0.0
ivyx
Analyze user messages for prompt injection attempts using Jev, refusing if detected or answering safely otherwise.
Steps
In the order the agent's file lists them. A branch or a loop is a step too; the wiring between steps is in the file.
- 01Ivy NodeJev · Noulivy.node.jev-noul
- 02Branchrefuse if injection detected
- 03Model turnrefuse the message
- 04Model turnanswer the message safely
Nodes it brings
Adding this agent in IVYX Studio adds these nodes with it. A node your workspace already has is kept as it is, even at another version.
What it touches
Collected from what each of its nodes declares, plus the model call when a step is a model turn. A declaration is the author's statement, and it is what policy rules select on.
What it needs
- A stored secret named
jev-api-key. The agent's file carries the name, never the value.
Inputs
| Field | Type | Description |
|---|---|---|
| messagerequired | Not declared | The text, or a JSON object or array, that Jev judges. |
Outputs
| Field | Type | Description |
|---|---|---|
| noul | number | The probability that the answer is yes, 0 to 1. |
| answer | boolean | True when noul reaches the threshold. |
| threshold | number | The threshold used. |
| model | string | The model version that answered. |
| response | string | safe answer |
Tests
2 of 2 test cases passed on Oct 2, 2026, in the publisher's own environment, before this version was published. The registry keeps that record; it does not run the cases again.
Requires: the stored secret jev-api-key, python:3.9
- injection
A request to ignore the instructions and print the system prompt is judged an override and refused.
- harmless
An ordinary question is answered.