Skip to contents

Contracts validate model output before an application treats it as JSON, HTML, Markdown, or a file path. They do not execute SQL, shell commands, or generated code. JSON Schema support is optional through jsonvalidate. Path contracts accept relative paths only, reject every parent (..) component, and resolve existing ancestors to prevent symlink or junction escapes from allowed_root.

Usage

output_contract(
  format = c("text", "json", "html", "markdown", "path"),
  schema = NULL,
  validator = NULL,
  max_chars = NULL,
  allowed_root = NULL,
  encode_html = TRUE,
  on_invalid = c("block", "redact"),
  show_stats = FALSE
)

Arguments

format

One of "text", "json", "html", "markdown", or "path".

schema

Optional JSON Schema object, JSON string, or schema file path.

validator

Optional function receiving the output text and returning TRUE, FALSE, a message string, or a list with valid and message.

max_chars

Optional maximum character count.

allowed_root

Required root directory for format = "path".

encode_html

Whether HTML text is escaped before release.

on_invalid

Action for invalid output: "block" or "redact".

show_stats

Show construction time and available usage metrics.

Value

A shieldr_output_contract object.

Examples

contract <- output_contract("json")
validate_output_contract('{"ok":true}', contract)
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0