scan_tool_call() validates tool-call intent and arguments before an
application executes the tool. It serializes the tool name and arguments,
scans that text with scan_prompt(), and applies the configured allowlist,
schema, authorization, validator, budget, and approval policy. The default
empty allowlist denies every tool.
Usage
scan_tool_call(
tool_name,
arguments = list(),
allowed_tools = character(),
policy = "enterprise_default",
reviewer = NULL,
checks = "rules",
redaction = NULL,
scanners = scanner_options(),
show_tokens = FALSE,
tool_policy = NULL,
subject = NULL,
state = NULL,
show_stats = FALSE
)Arguments
- tool_name
Tool name requested by a model or orchestrator.
- arguments
Tool arguments as a list, data frame, character string, or other JSON-serializable value.
- allowed_tools
Character vector of approved tool names. The default empty vector denies every tool;
NULLexplicitly disables the allowlist.- policy
A
shieldr_policyor built-in policy name.- reviewer
Optional reviewer function or object with
$chat().- checks
One of
"rules","nlp","llm", or"both".- redaction
Optional redaction strategy from
redaction_strategy().- scanners
Optional scanner configuration from
scanner_options().- show_tokens
Whether to attach token counts when
ellmeris available.- tool_policy
Optional richer policy from
tool_policy().- subject
Optional authorization context passed to the tool policy.
- state
Optional mutable call-limit state used by guarded dispatchers.
- show_stats
Show execution statistics as messages.
Details
This helper does not execute tools. It is designed to sit immediately before
an application-level dispatcher. Use allowed_tools for a simple allowlist,
and use normal policy rules or custom rules to validate argument content.
The returned shieldr_report() stores stage = "tool_call" and tool_name
in metadata, so audit logs can distinguish tool input checks from prompt,
context, and output checks.
