Creates a validated rule for the llmshieldr rule engine. Rules map to OWASP LLM Top 10:2026 categories where possible; see https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/tree/main/2026/final.
Usage
shieldr_rule(
id,
pattern = NULL,
fn = NULL,
owasp = NULL,
severity = "medium",
action = "redact",
description = "",
stages = c("prompt", "context", "output", "tool_call", "tool_output", "document"),
confidence = NULL,
show_stats = FALSE
)Arguments
- id
A unique rule identifier.
- pattern
A regular expression pattern, or
NULL.- fn
A predicate function, or
NULL.- owasp
Optional OWASP LLM category such as
"llm01".- severity
One of
"low","medium","high", or"critical".- action
One of
"allow","redact", or"block".- description
Human-readable rule description.
- stages
Stages where the rule runs. Defaults to all text stages.
- confidence
Optional detector confidence between 0 and 1. Severity remains an impact measure and action remains a policy decision.
- show_stats
Show construction time and available usage metrics.
Details
A rule is the atomic unit of a policy. Each rule either supplies a regular
expression pattern or an R function. Regex rules are applied with
gregexpr(..., perl = TRUE) and can produce character spans for redaction.
Function rules receive the full text and can return TRUE, FALSE, a
finding list, a list of finding lists, or a data frame of findings.
severity is converted to a numeric score by the scanner:
low:0.1medium:0.3high:0.6critical:1.0
The scanner caps the summed report score at 1.0. Critical findings and
rules with action = "block" force the resolved report action to block.
Examples
shieldr_rule(
id = "demo.email",
pattern = "\\\\b[^@]+@example\\\\.com\\\\b",
owasp = "llm02",
description = "Example-domain email address"
)
#> Warning: Rule id "demo.email" does not follow the `llmXX.` naming convention.
#> ℹ `risk_summary()` groups findings by OWASP prefix; non-conforming ids will
#> appear under an "NA" category.
#> $id
#> [1] "demo.email"
#>
#> $pattern
#> [1] "\\\\b[^@]+@example\\\\.com\\\\b"
#>
#> $fn
#> NULL
#>
#> $owasp
#> [1] "llm02"
#>
#> $severity
#> [1] "medium"
#>
#> $action
#> [1] "redact"
#>
#> $description
#> [1] "Example-domain email address"
#>
#> $stages
#> [1] "prompt" "context" "output" "tool_call" "tool_output"
#> [6] "document"
#>
#> $confidence
#> NULL
#>
#> attr(,"class")
#> [1] "shieldr_rule"
