文件 v1.1.1

System Prompt 保護

·

Agenvoy 如何防止 system prompt 被取出或覆寫。

System prompt(configs/prompts/system_prompt/system_prompt.md)結尾有一段優先於 skill、使用者指示與對話脈絡的規則。符合下列任一類別的請求,模型只會回覆 sentinel 加上規則 id,即 [KARAPPO] <rule id>;runtime 接著將其替換為拒絕訊息,並在括號中附上規則 id(v1.0.23 起),該回合不寫入歷史:

自 v1.0.23 起清單只剩這三類。原本的「揭露 system prompt」與「身分探測」兩類已移除,範圍較廣的「機密」類別則收斂為 secret-exfil。

這些是 prompt 中的 policy,非 Go 端硬編碼的 filter。自 v1.0.21 起類別清單移至 configs/jsons/guardrail_rules.json,同時注入 agent 與 Chat Completions 兩份 system prompt,新增類別只需編輯該檔。拒絕文字取自 configs/jsons/refusal_messages.json,依設定的 reply_lang 選擇;auto 或未收錄的語言退回英文(This operation cannot be performed)。v1.0.21 之前拒絕文字固定為 無法執行此操作。

EN