GuardrailMiddleware

org.llm4s.agent.graph.middleware.GuardrailMiddleware
See theGuardrailMiddleware companion object
final class GuardrailMiddleware(input: Seq[InputGuardrail], output: Seq[OutputGuardrail], val id: MiddlewareId) extends AgentMiddleware

Runs input guardrails on the run's input (beforeAgent) and output guardrails on its final answer (afterAgent). Each list runs in order, each guardrail on the value the previous one returned, so a Fix transforms; a Warn passes. Failures are collected and fail the run with the error CompositeGuardrail.all reports. A guardrail does not suspend.

Attributes

Companion
object
Graph
Supertypes
class Object
trait Matchable
class Any

Members list

Value members

Concrete methods

override def afterAgent(answer: String, context: RunContext): Result[String]

Sees the run's final answer: returns it, possibly changed, or Left to fail the run.

Sees the run's final answer: returns it, possibly changed, or Left to fail the run.

Attributes

Definition Classes
override def beforeAgent(text: String, context: RunContext): Result[String]

Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.

Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.

Attributes

Definition Classes

Inherited methods

Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.

Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.

Attributes

Inherited from:
AgentMiddleware

Middleware this one must run outside of (wrap); each must be registered in the same stack.

Middleware this one must run outside of (wrap); each must be registered in the same stack.

Attributes

Inherited from:
AgentMiddleware
def tools: Vector[AgentTool[_]]

Tools this middleware contributes; they join the loop's tool set and are validated like any other.

Tools this middleware contributes; they join the loop's tool set and are validated like any other.

Attributes

Inherited from:
AgentMiddleware

Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. A model wrapper cannot suspend.

Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. A model wrapper cannot suspend.

Filtering ModelRequest.tools shapes what the model is offered and is not a permission control: a tool the model calls anyway still runs through wrapToolCall, where denial belongs.

Attributes

Inherited from:
AgentMiddleware
def wrapToolCall(request: ToolCallRequest, context: ToolContext)(next: () => ToolOutcome): ToolOutcome

Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.

Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.

Attributes

Inherited from:
AgentMiddleware
def writes: Set[StateKey[_, _]]

The state keys this middleware's wrapToolCall may add to a Success update.

The state keys this middleware's wrapToolCall may add to a Success update.

Attributes

Inherited from:
AgentMiddleware

Concrete fields

This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.

This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.

Attributes