Skip to main content
Use this on incoming messages and retrieved text that an assistant might read. Keep the material being classified separate from the instructions governing your application. Open this recipe in the playground, or set D1_API_KEY as in the quickstart and run the same request:

Use the result

Read decisions.attack.p_yes and the full distribution. Choose a threshold on reviewed attack and benign examples; send uncertain cases to your application’s established review or constrained-processing path. A no answer is not permission to trust the text. Preserve instruction boundaries and restrict tool permissions independently of this score. Attackers can phrase malicious instructions indirectly, while benign documents may quote examples of attacks. Evaluate both missed attacks and false alarms. Include your retrieval formats, encoded or multilingual text, indirect instructions in documents, and benign security discussions. Re-run this set when changing wording or model versions.

What was evaluated

The historical benchmark measures the attack decision on the specified dataset. It does not establish resistance to unseen attacks or guarantee that a downstream agent will preserve its instruction hierarchy.
Historical evaluation on 2026-09-28, using sqwish-d1-core. These measurements describe that checkpoint and dataset, not current production performance or an accuracy guarantee.
  • Dataset: PromptShield (Apache-2.0).
  • Split: validation.
  • Sample: 960 rows, 960 measured decisions.
  • Measured decision IDs: attack.
  • Wording: tuned.
  • Checkpoint SHA-256: dd420ca652cfaa10279eabb54d15afd50fe9d24d357498c4dbc512b1c3d73bb2.
The majority-class baseline has accuracy 0.5031; the class-prior baseline has log loss 0.6931. Only the decision IDs listed above were measured. Dataset labels, class balance and wording affect these results. The intervals do not measure distribution shift. Re-evaluate with your own cases, including ambiguous and out-of-scope inputs.

Improve it for your application

Keep the decision IDs and outcome order stable while evaluating changes. Review a dataset, tune the wording, and compare the result against your current policy before changing production. Check fallback so you know which model actually answered.