Skip to contents

Scans arguments, executes only an allowed request, then scans the tool result before returning it. This is the provider-neutral dispatcher for chat SDKs that do not expose request/result hooks.

Usage

guard_tool(
  tool_name,
  arguments = list(),
  dispatcher,
  tool_policy,
  subject = NULL,
  policy = "enterprise_default",
  reviewer = NULL,
  checks = "rules",
  redaction = NULL,
  scanners = scanner_options(),
  show_tokens = FALSE,
  show_stats = FALSE
)

Arguments

tool_name

Tool name.

arguments

Named argument list.

dispatcher

Function accepting (tool_name, arguments), or a named list of tool functions called with do.call().

tool_policy

Policy from tool_policy().

subject

Optional authorization context passed through unchanged.

policy

A shieldr_policy or built-in policy name.

reviewer

Optional reviewer function or object with $chat().

checks

One of "rules", "nlp", "llm", or "both".

redaction

Optional redaction strategy from redaction_strategy().

scanners

Optional scanner configuration from scanner_options().

show_tokens

Whether to attach token counts when ellmer is available.

show_stats

Show execution statistics as messages.

Value

A list with action, value, call_report, and output_report.

Examples

dispatcher <- list(search = function(query) paste("result", query))
guard_tool(
  "search", list(query = "public"), dispatcher,
  tool_policy(allowed_tools = "search")
)
#> $action
#> [1] "allow"
#> 
#> $value
#> [1] "result public"
#> 
#> $call_report
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0
#> 
#> $output_report
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0
#>