Skip to contents

Creates a validated rule for the llmshieldr rule engine. Rules map to OWASP LLM Top 10:2026 categories where possible; see https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/tree/main/2026/final.

Usage

shieldr_rule(
  id,
  pattern = NULL,
  fn = NULL,
  owasp = NULL,
  severity = "medium",
  action = "redact",
  description = "",
  stages = c("prompt", "context", "output", "tool_call", "tool_output", "document"),
  confidence = NULL,
  show_stats = FALSE
)

Arguments

id

A unique rule identifier.

pattern

A regular expression pattern, or NULL.

fn

A predicate function, or NULL.

owasp

Optional OWASP LLM category such as "llm01".

severity

One of "low", "medium", "high", or "critical".

action

One of "allow", "redact", or "block".

description

Human-readable rule description.

stages

Stages where the rule runs. Defaults to all text stages.

confidence

Optional detector confidence between 0 and 1. Severity remains an impact measure and action remains a policy decision.

show_stats

Show construction time and available usage metrics.

Value

A shieldr_rule S3 object.

Details

A rule is the atomic unit of a policy. Each rule either supplies a regular expression pattern or an R function. Regex rules are applied with gregexpr(..., perl = TRUE) and can produce character spans for redaction. Function rules receive the full text and can return TRUE, FALSE, a finding list, a list of finding lists, or a data frame of findings.

severity is converted to a numeric score by the scanner:

  • low: 0.1

  • medium: 0.3

  • high: 0.6

  • critical: 1.0

The scanner caps the summed report score at 1.0. Critical findings and rules with action = "block" force the resolved report action to block.

Examples

shieldr_rule(
  id = "demo.email",
  pattern = "\\\\b[^@]+@example\\\\.com\\\\b",
  owasp = "llm02",
  description = "Example-domain email address"
)
#> Warning: Rule id "demo.email" does not follow the `llmXX.` naming convention.
#> ℹ `risk_summary()` groups findings by OWASP prefix; non-conforming ids will
#>   appear under an "NA" category.
#> $id
#> [1] "demo.email"
#> 
#> $pattern
#> [1] "\\\\b[^@]+@example\\\\.com\\\\b"
#> 
#> $fn
#> NULL
#> 
#> $owasp
#> [1] "llm02"
#> 
#> $severity
#> [1] "medium"
#> 
#> $action
#> [1] "redact"
#> 
#> $description
#> [1] "Example-domain email address"
#> 
#> $stages
#> [1] "prompt"      "context"     "output"      "tool_call"   "tool_output"
#> [6] "document"   
#> 
#> $confidence
#> NULL
#> 
#> attr(,"class")
#> [1] "shieldr_rule"