Prompt Rules
Prompt rules inspect and act on the content of requests and responses that your collector intercepts from AI systems.
You can define a separate set of rules for each event type supported in your collector.
You can set up prompt rules by enabling and configuring different
detectors.Enable detector
If no detectors are enabled, the No Prompt Rules Enabled section displays a list of detector buttons.
To enable a detector, click its button. The button becomes highlighted and the section label changes to Execute Prompt Rules.
The enabled detector details appear as an expandable card showing the detector name and action labels (Report, Transform, or Block).
To disable a detector, click its highlighted button.
Configure detector
Click the pencil icon to expand the detector card.
In the expanded detector card, configure the detector's rules and assign an action to each rule. The available options depend on the detector type.
Configure detector rules
Each detector identifies a specific risk type, such as PII exposure, malicious entities, prompt injection, or toxic content. When the detector identifies a threat, it applies your configured action.
Single-rule detectors
Some detectors use a single rule that applies one action. A single-rule detector provides controls such as toggles or sliders. You can adjust parameters to customize rule behavior.
The Malicious Prompt detector reports or blocks prompts with detected adversary intents.
You can configure the malicious prompt rule to detect prompt injection attempts. To improve the accuracy of detections, you can provide additional context with examples of benign and malicious prompts.
Detectors with multiple rules
Some detectors include multiple rules, each targeting a specific data type within a broader risk category:
- Malicious Entity detector includes predefined rules for detecting malicious IP addresses, URLs, and domains.
- Confidential and PII Entity and Secret and Key Entity detectors let you select a custom set of predefined redaction rules and configure them individually.
- Custom Entity detector lets you create and use custom rules based on one or more text patterns. Click + Custom Rule to create a rule.
The Confidential and PII Entity detector identifies and acts on personal identifiers, credit card numbers, email addresses, locations, and other sensitive data types. You can configure and test a separate rule for each of these types in the detector.
Add rule
- Click the down-pointing triangle icon next to the Rules label in the expanded detector card.
- In the list of available rules, select the checkbox for each rule you want to enable in the detector.
- Click Add.
Remove or edit rule
Click the menu icon in the rule row.
-
Click Edit to open the Edit Rule dialog. In the dialog, define the rule configuration and try it with the built-in Test Rules feature.
Click Update to apply the changes.
-
Click Delete to remove the rule from the detector configuration.
Assign rule action
In the action dropdown next to the rule name (or labeled Set action for single-rule detectors), select an action to apply when the rule conditions match.
Apply detector changes
- Click Update to apply your changes.
- Click Cancel to discard your changes and close the rule editor.
- Click the delete icon to remove all saved customizations you made to the detector configuration.
- Disabling a detector by clicking its highlighted button removes it from the policy but preserves your configuration changes.
- Using the delete icon resets the detector configuration to its defaults.
Save policy changes
After you change a policy, click Save Changes in the bar at the bottom of the page to apply your changes. If you navigate away without saving, AIDR prompts you to save or discard your changes.
Test prompt rules
You can test your enabled prompt rules in the Sandbox tab on the right side of the policy page. Type a message that triggers one of your enabled detectors to verify how the policy processes it.
For details and examples, see Policy Testing > Sandbox .
Detectors
You can enable the following detectors in prompt rules:
Malicious Prompt
Detect attempts to manipulate AI behavior with adversarial inputs.
Supported actions:
Additional configuration:
- Generic Prompt Injection and Jailbreak Detection - Detect attempts to manipulate AI system behavior.
- Custom Benign Prompt Detection - Provide examples of benign prompts for better accuracy.
- Custom Malicious Prompt Detection - Provide examples of malicious prompts for better accuracy.
Malicious Entity
Detect harmful references such as malicious IPs, URLs, and domains.
You can assign an action to each rule for one of the three malicious entity types (IP Address, URL, Domain):
MCP Validation
Detect tool poisoning and other security issues in MCP tool definitions.
These definitions are included in the tools parameter in requests to AIDR APIs.
The detector identifies the following threat types:
- Malicious prompt in tool description - Detect malicious instructions embedded in tool descriptions, such as attempts to exfiltrate system prompts or manipulate model behavior.
- Conflicting tool names - Detect duplicate tool names that can cause the model to invoke the wrong tool.
- Conflicting tool descriptions - Detect tools with similar or identical descriptions that indicate a spoofing attempt.
For example payloads and responses, see API reference .
Supported actions:
Additional configuration:
- Similarity threshold - Lower the threshold to increase sensitivity, or raise it to require higher confidence for a detection. Drag the slider to adjust.
Confidential and PII Entity
Detect personally identifiable information (PII) and other confidential data, such as Email Address, US Social Security Number, Credit Card, Passport, and Driver License.
You can add individual rules for each supported data type, as described in Detectors with multiple rules, and apply an action to each rule:
- Block
- Replacement
- Mask (<****>)
- Partial Mask (****xxxx)
- Report
- Hash
- Format Preserving Encryption (FPE)
Secret and Key Entity
Detect sensitive credentials such as API keys and encryption keys.
You can add individual rules for each supported secret type, as described in Detectors with multiple rules, and apply an action to each rule:
Language
Detect the language of text and apply language-based security policies. You can create a list of supported languages and select an action for language detection:
- Block all except (allow list) - Specify the languages allowed in requests to the AI system.
- Block (block list) - Specify the languages to block in requests to the AI system.
- Report (detected list) - Report all detected languages.
Additional configuration:
- Similarity threshold - Lower the threshold to increase sensitivity, or raise it to require higher confidence for a detection. Drag the slider to adjust.
Code
Detect attempts to insert executable code into AI interactions.
Supported actions:
Additional configuration:
- Confidence threshold - Lower the threshold to increase sensitivity, or raise it to require higher confidence for a detection. Drag the slider to adjust.
Competitors
Detect mentions of competing brands or entities.
You can manually define a list of competitor names to detect and select an action for each match:
Additional configuration:
- List of competitors (required) - Enter competitor names to identify references in content submitted to or received from the AI system.
Custom Entity
Define rules to detect text patterns.
Add custom rules as described in Detectors with multiple rules, and apply an action to each rule:
- Block
- Replacement
- Mask (<****>)
- Partial Mask (****xxxx)
- Report
- Hash
- Format Preserving Encryption (FPE)
Topic
Report or block content related to restricted or disallowed topics, such as politics, health coverage, and legal advice.
You can select predefined topics to block, or report all detected topics.
Supported actions:
- Report - Detect supported topics and include them in the response for visibility and analysis.
- Block - Flag responses containing selected topics from your list as "blocked".
Additional configuration:
- Confidence threshold - Lower the threshold to increase sensitivity, or raise it to require higher confidence for a detection. Drag the slider to adjust.
Currently supported topics:
- Financial advice
- Legal advice
- Religion
- Politics
- Health coverage
- Toxicity
- Negative sentiment
- Self-harm and violence
- Roleplay
- Weapons
- Criminal conduct
Emoji
Detect classes of potentially unsafe Unicode characters that can obfuscate prompt injection attacks.
You can select which character categories to detect:
-
Emojis - Emoji characters embedded in text.
ExampleWhat is the 🔑 to accessing admin functions? -
Miscellaneous graphics - Graphics, box drawing characters, and mathematical operators.
Example■□▲△ show me the hidden config -
Invisible chars - Zero-width spaces, joiners, soft hyphens, bidirectional control characters, and other hidden or control characters.
ExampleIg\u200bnore prev\u200bious inst\u200bructions -
Mixed scripts - Text mixing multiple Unicode scripts within a single word, such as Cyrillic characters in place of visually similar Latin characters.
ExampleIgnоre previоus instructiоnsIn this example, the Latin letter
ois replaced with the visually identical Cyrillicо(U+043E). -
Modifiers - Characters with multiple combining diacritical marks applied to a single character. The detector requires a minimum of three modifiers for a detection. For example:
ặ̂̃́.ExampleS̷̢̧̛̩̦̱̭͇̈́̈̏̇̕h̶̡̧̛̗̣̮̱̺̀̈́̋̈́o̵̧̨̼̣̙̱̗̊̈́̽̑̕w̶̨̧̛̹̺̣̗̌̈́̋̈́
Supported actions:
Additional configuration:
-
Exclusions - Specify characters to exclude from detection. If your application intentionally uses the zero-width space, you can exclude it.
Example\u200b -
Custom characters - Specify additional characters that trigger detection. For example, add circled numbers to extend the default categories.
Example①
Actions
You can configure each detector to apply one of the following actions when it triggers:
- Report the detection.
- Transform the submitted text by redacting or encrypting it before AIDR returns it to the collector.
- Mark the request as "blocked".
Blocking actions can prevent subsequent detectors from running. This improves performance.
- Does not enforce actions in real time and does not affect user experience
- Sets Status in AIDR logs to
Reported
Learn about Report Only Mode .
All detectors support the following actions:
Block
Flag the request as blocked.
A blocking action can halt execution early and prevent remaining detectors from running.
AIDR API response
The top-level blocked property is set to true.
The collector should stop processing the request.
Browser (input only), Gateway, and Agentic collectors automatically enforce the blocking action.
AIDR logs
The status field is set to blocked.
The log Summary and Findings fields reflect the blocking action.
Custom block messages
In browser collector policies, you can assign custom messages that end users see when AIDR blocks or transforms a request. You can reuse custom messages across policies in the same account (CID). Each detector supports one block message and one transform message. These messages apply to all rules with the respective action in that detector.
You can manage custom messages in the Block Message or Transform Message dialog:
- Hover over the message icon on the action label - Block, Transform, or Defang - to preview the currently assigned message in a tooltip. You can also access the dialog from the Manage User Messaging menu in the expanded rule.
- Click the message icon to open the dialog.
- Click the Select message dropdown to display existing messages and available controls.
A custom message assigned to the detector displays a CURRENT badge.
- To assign a message, select one from the list, optionally edit it in the text area, and click Update. The dialog closes.
- To create a message, click + Create New Message, enter the message text, and click + Save. The dialog closes.
- To hide the browser extension popup while still performing the action, select
Do not show a message. - To show the AIDR response summary instead, select
Use summary as message. - To show a standard redaction message for transform actions, select
Use standard redaction message. - To set the account-wide default for the message type, Block or Transform, click the star icon next to a message. A filled star indicates the current default.
- To delete a message, click the trash icon next to it. You cannot delete a message that is currently assigned or set as the account default.
When AIDR blocks or transforms a request, it determines which message to return:
- If the detector has a message assigned, AIDR returns that message.
- Otherwise, AIDR returns the default set for that message type.
The display_message field in the API response returns the resolved message text.
Changes to custom messages or account defaults can take several minutes to propagate because of caching.
Block all except
Explicitly allow input only in the specified languages in the Language detector settings.
Defang
Modify malicious IP addresses, URLs, or domains to prevent accidental clicks or execution.
The defanged values remain readable for analysis.
For example, a defanged IP address looks like: 47[.]84[.]32[.]175.