D1_API_KEY as in the quickstart and run the same request:
Use the result
Readdecisions.attack.p_yes and the full distribution. Choose a threshold on reviewed attack and benign examples; send uncertain cases to your application’s established review or constrained-processing path.
A no answer is not permission to trust the text. Preserve instruction boundaries and restrict tool permissions independently of this score. Attackers can phrase malicious instructions indirectly, while benign documents may quote examples of attacks.
Evaluate both missed attacks and false alarms. Include your retrieval formats, encoded or multilingual text, indirect instructions in documents, and benign security discussions. Re-run this set when changing wording or model versions.
What was evaluated
The historical benchmark measures theattack decision on the specified dataset. It does not establish resistance to unseen attacks or guarantee that a downstream agent will preserve its instruction hierarchy.
Historical evaluation on 2026-09-28, using sqwish-d1-core. These measurements describe that checkpoint and dataset, not current production performance or an accuracy guarantee.
- Dataset: PromptShield (Apache-2.0).
- Split: validation.
- Sample: 960 rows, 960 measured decisions.
- Measured decision IDs:
attack. - Wording: tuned.
- Checkpoint SHA-256:
dd420ca652cfaa10279eabb54d15afd50fe9d24d357498c4dbc512b1c3d73bb2.
The majority-class baseline has accuracy 0.5031; the class-prior baseline has log loss 0.6931.
Only the decision IDs listed above were measured. Dataset labels, class balance and wording affect these results. The intervals do not measure distribution shift. Re-evaluate with your own cases, including ambiguous and out-of-scope inputs.
