{"ok":true,"engine":"sentinel402-prompt/1","engineVersion":"1.0.0","count":13,"rules":[{"id":"PI_INSTRUCTION_OVERRIDE","label":"Instruction-override attempt","severity":"critical","defaultOn":true,"hint":"The canonical injection opener. Treat everything after it as attacker-controlled."},{"id":"PI_SYSTEM_PROMPT_LEAK","label":"System-prompt exfiltration attempt","severity":"critical","defaultOn":true},{"id":"PI_HIDDEN_UNICODE_TAGS","label":"Invisible Unicode tag characters (hidden payload)","severity":"critical","defaultOn":true,"hint":"Invisible characters that models still read. Strip U+E0000-U+E007F before this text reaches a context window."},{"id":"PI_ZERO_WIDTH_RUN","label":"Zero-width character cluster (steganographic text)","severity":"high","defaultOn":true},{"id":"PI_ROLE_HIJACK","label":"Role-hijack / mode-switch attempt","severity":"high","defaultOn":true},{"id":"PI_JAILBREAK_KEYWORD","label":"Jailbreak / guardrail-bypass language","severity":"high","defaultOn":true},{"id":"PI_ROLE_MARKER","label":"Fake chat-role delimiter / template injection","severity":"high","defaultOn":true,"hint":"Untrusted text should never contain chat-template control tokens; a model may treat them as real role boundaries."},{"id":"PI_CREDENTIAL_EXFIL","label":"Credential-exfiltration instruction","severity":"high","defaultOn":true},{"id":"PI_FINANCIAL_EXFIL","label":"Fund-transfer instruction","severity":"high","defaultOn":true,"hint":"Content that instructs an agent to move money is a transaction request, not data. Require out-of-band confirmation."},{"id":"PI_HTML_COMMENT_INSTR","label":"Instruction hidden in an HTML comment","severity":"medium","defaultOn":true},{"id":"PI_EXFIL_IMAGE","label":"Markdown image beacon (context exfiltration channel)","severity":"medium","defaultOn":true,"hint":"Rendered UIs auto-fetch image URLs — attacker-controlled markdown can smuggle context out as query parameters."},{"id":"PI_BASE64_BLOB","label":"Long base64-like blob (possible obfuscated payload)","severity":"medium","defaultOn":true,"hint":"Not proof of injection — but hidden instructions are often base64'd to slip past keyword filters. Decode out-of-band."},{"id":"PI_EVAL_DECODE","label":"Decode-and-evaluate instruction","severity":"low","defaultOn":true}]}