Back to docs

API Reference

POST /intercept/output

POST/api/v1/intercept/output

Checks what flows back to your agent before it reads or shows it: a model answer, or the result of a tool, web page, file or email. Many attacks hide instructions in content an agent reads rather than in what a user types. Secrets and personal data are masked, and text that tries to give instructions to the AI is blocked.

Request

{
  "output": string   // Required. The text your agent is about to read.
}

What to do with the response

  • allowed: false: the content tries to instruct the AI. Do not pass it to the model, or pass it clearly marked as untrusted data.
  • Redact: use redacted_payload, which has secrets and personal data masked.
  • A shell command that is only mentioned in the text is flagged, not blocked: text is not execution. Check commands the agent is about to run with /intercept/command.

The response has the same fields as /intercept/prompt.