Class: Kodo::Web::InjectionScanner

Inherits:
Object
  • Object
show all
Defined in:
lib/kodo/web/injection_scanner.rb

Overview

Detection-only scanner for common prompt injection patterns in web content.

IMPORTANT: This is not a security boundary. An attacker who reads Kodo's source can phrase injections to avoid these patterns. The scanner's value is in catching unsophisticated/automated attacks and producing audit events. The actual security boundary is the nonce-based content isolation in TurnContext.

Defined Under Namespace

Classes: Result

Constant Summary collapse

PATTERNS =

Patterns that commonly appear in prompt injection attempts. Deliberately broad — false positives are acceptable since we only log, not block.

[
  /ignore\s+(all\s+)?previous\s+instructions?/i,
  /disregard\s+(all\s+)?previous\s+instructions?/i,
  /forget\s+(all\s+)?previous\s+instructions?/i,
  /you\s+are\s+now\s+a\s+/i,
  /new\s+instructions?:/i,
  /system\s+prompt:/i,
  /\[\s*system\s*\]/i,
  /exfiltrate/i,
  /send\s+(all\s+)?memory\s+to/i,
  /reveal\s+(your\s+)?(system\s+)?prompt/i,
  /print\s+(your\s+)?(system\s+)?prompt/i,
  /override\s+(your\s+)?directives?/i,
  /DAN\s+mode/i,
  /jailbreak/i
].freeze

Class Method Summary collapse

Class Method Details

.scan(text) ⇒ Object



38
39
40
41
42
43
44
45
46
47
# File 'lib/kodo/web/injection_scanner.rb', line 38

def self.scan(text)
  return Result.new(signal_count: 0, signals: []) if text.nil? || text.empty?

  matched = PATTERNS.filter_map do |pattern|
    match = text.match(pattern)
    match[0] if match
  end

  Result.new(signal_count: matched.length, signals: matched)
end