Text Extraction

Extract the text that guardrails scan from a chat completion request or response, and.

write guardrails’ changes back.

  • Input guardrails scan the latest user message: what the user just said. They do not scan the LLMClient’s own system prompt, which would make e.g. a prompt injection guardrail trigger on the operator’s instructions, nor the earlier turns of the conversation, which were scanned when they were new.

  • Output guardrails scan the reply’s message content, and refusal.

A message’s content may be a string, or a list of parts, of which the text parts are scanned. Each segment has a path, e.g. messages[3].content or messages[3].content[0].text, so that redactions can be written back to the right place.

smarter.apps.guardrail.services.text_extraction.extract_segments(payload, stage)[source]

Return the text segments that guardrails scan, for a payload and stage.

Parameters:
  • payload (dict[str, Any]) – A chat completion request (messages) for the pre stage, or response (choices) for the post stage.

  • stage (GuardrailStage) – Which side of the model call the payload is.

Return type:

list[TextSegment]

Returns:

The segments, in document order. Empty or non-text fields are omitted.

smarter.apps.guardrail.services.text_extraction.latest_user_message_index(messages)[source]

Return the index of the latest message whose role is user, or None.

Return type:

int | None

smarter.apps.guardrail.services.text_extraction.read_segment(payload, path)[source]

Return the text at path, or None if it does not resolve to a string.

Return type:

str | None

smarter.apps.guardrail.services.text_extraction.resolve_path(payload, path)[source]

Walk a messages[0].content-style path to its final container.

Return type:

tuple[Any, Any]

Returns:

(container, key), such that container[key] is the field that path names, or (None, None) if the path does not resolve.

smarter.apps.guardrail.services.text_extraction.write_segment(payload, path, new_text)[source]

Return a deep copy of the payload, with the text at path replaced.

If path does not resolve, the copy is returned unchanged.

Return type:

dict[str, Any]