Contracts validate model output before an application treats it as JSON,
HTML, Markdown, or a file path. They do not execute SQL, shell commands, or
generated code. JSON Schema support is optional through jsonvalidate.
Path contracts accept relative paths only, reject every parent (..)
component, and resolve existing ancestors to prevent symlink or junction
escapes from allowed_root.
Arguments
- format
One of
"text","json","html","markdown", or"path".- schema
Optional JSON Schema object, JSON string, or schema file path.
- validator
Optional function receiving the output text and returning
TRUE,FALSE, a message string, or a list withvalidandmessage.- max_chars
Optional maximum character count.
- allowed_root
Required root directory for
format = "path".- encode_html
Whether HTML text is escaped before release.
- on_invalid
Action for invalid output:
"block"or"redact".- show_stats
Show construction time and available usage metrics.
Examples
contract <- output_contract("json")
validate_output_contract('{"ok":true}', contract)
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0
