How the gateway treats text a site wrote.
A website can put anything in its pages. The gateway labels that text as data, cleans it, and never lets it start an action.
Labelled
Their words stay theirs.
Anything a site wrote, from a page to a business name, comes back marked untrusted, with where it came from and when it was read. A notice at the top tells the agent not to follow it.
Cleaned
Cleaned and flagged, not blocked.
Hidden text, invisible characters and comments are stripped. Text that reads like an instruction is flagged and still passed on: a plumber whose page says “ignore previous instructions” is still a plumber.
Actions
Nothing a page says can start one.
Every action needs details the user gave, and where required the user’s own yes in their chat. Returned text cannot supply either, and tool descriptions never contain site text.
Limits
What this does not catch.
Text hidden by a stylesheet class can get through, because hiding by class cannot be judged without the stylesheet. The flags and the notice are the backstop. This labels text; it does not vouch for it.
For developers
The envelope, field by field.
Five tools return text written by third parties and carry untrustedContent: read_page, inspect_site, find_business, list_actions and describe_action. The envelope puts the notice first, then these fields, then the result’s own keys.
untrustedProvenance- The source page or origin, and fetchedAt, when it was read. The source is frontlatch-index when the text came from the index.
injectionSuspected- True when any string matched an instruction-shaped pattern, false otherwise.
injectionFlags- One entry per match: the pattern name and the path of the field it was found in, such as actions[3].label.
sanitised- True when at least one string had something removed or was cut to its length cap.
What is stripped
- Control characters, and zero-width, bidirectional, word-joiner and byte-order-mark characters, plus Unicode tag characters.
- HTML comments, in every string and in the page itself.
- From a page: script, style, noscript, template, iframe, object, embed, svg and hidden inputs.
- Elements with the
hiddenattribute oraria-hidden="true", and elements whose inline style hides, shrinks, makes transparent or moves them off-screen. - Short fields have whitespace collapsed and are capped at 300 characters; every string, object keys included, goes through the same pass.
Detection flags, it does not block
Pattern names include ignore-previous-instructions, role-override, fake-role-marker, tool-call-instruction, confirmation-forgery, secrecy-demand, exfiltration and agent-addressed. Matching runs on the raw text as well as the cleaned text, so stripping an invisible character cannot hide a payload from the flag. Flagged text is still returned.
The class-hidden-text limit
Only inline styles and attributes are judged. Text hidden by a CSS class is not removed; the flags and the notice cover what remains.
Static tool descriptions
Tool descriptions are constants in the gateway. No website, business name or index entry is ever written into one, so a site cannot poison a description.
Acting tools
do, do_action and signup need explicit parameters and, where required, user_confirmed (or confirm), set only after the user agreed in their own chat. No returned content can supply either. Details are in the developer quickstart.
See the gateway.
What an assistant sees, and what it can ask for.