Skip to main content
Web pages, emails, and documents can hide instructions aimed at your agent, such as a comment telling it to email your customer list somewhere. Screen untrusted content with GLiDE before it reaches the agent’s context, and drop or quarantine anything that tries to give orders.

Request

Pass the content and the tools the agent could misuse. Listing the tools helps GLiDE judge how much damage the content could do.

Request schema

Response

Measured against https://api.fastino.ai. Confidence values vary slightly between calls.
risk.score is 3, the fourth level counted from 0: “Critical: private data could leave the company”.

Response schema

Act on the answer

The bar to pass content through is high on purpose. A false alarm costs one page; a missed injection can leak data.

Adapt it

  • Screen every untrusted source: fetched pages, inbound email, uploaded files, and tool results.
  • Send hidden text as well as visible text. HTML comments, alt text, and white-on-white text are common hiding places.
  • List the agent’s real tools in state.agent_tools, so risk reflects what the agent could actually do.
  • Add a phishing path if people read the same content, and route it to your security team.
Screening reduces injection risk but does not remove it. Also limit the agent’s permissions, and require confirmation before it sends data or money.

Policy and safety guide

Design gates that fail safely on uncertainty.

GLiDE API reference

Every field, limit, and error for POST /v1/systemone.