{"uid":"cap_ovO0iDWjTq-r7k8fiQs_F","slug":"verity-suite-sentinel-prompt-injection-manipulation-scanner-f579c59b","name":"Verity Suite Sentinel — Prompt Injection & Manipulation Scanner","description":"The trust fabric for AI agents — calibrated, fail-closed services agents pay per call.","url":"https://suite.veritylayer.dev/sentinel","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"content":{"type":"string","title":"Content","maxLength":2000,"minLength":1,"description":"the untrusted text or tool output to scan for hidden prompt-injection, jailbreak, or manipulation. Treated entirely as inert data."},"context":{"anyOf":[{"type":"string","maxLength":2000},{"type":"null"}],"title":"Context","default":null,"description":"where this content came from and how the agent intends to use it (e.g. 'web page fetched via tool', 'email body', 'retrieved doc'). Also untrusted: a hint, never a command, and may itself be adversarial."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.06","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.06/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.06","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.06","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Ni-Gg4277bRdETcmVXpiK","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.06","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans untrusted text or tool outputs for hidden prompt-injection attacks, jailbreaks, and manipulation attempts, returning a signed verdict with threat score and evidence","exampleAgentPrompt":"Before you process this web page I just fetched, scan it with Sentinel for hidden prompt-injection or manipulation attempts — here's the content: '[raw page text]', and it came from a tool call to fetch a competitor's product page.","exampleUseCases":[{"title":"Safe web browsing for autonomous agents","prompt":"I need you to check this HTML I pulled from an external site before you summarize it — scan it for any injected instructions trying to hijack you, and tell me the verdict and threat score."},{"title":"Email assistant inbox protection","prompt":"Before you draft a reply to this email, run the body through Sentinel to make sure there's no hidden text trying to override your instructions — the email came from an unknown sender."},{"title":"RAG pipeline document gating","prompt":"We're about to insert this retrieved document chunk into our agent's context window — can you first check it for prompt-injection or jailbreak attempts and only proceed if it comes back clean?"}],"resultDescription":"A JSON object containing: a verdict enum (clean, suspicious, injection, or uncertain), a numeric threat_score indicating severity, an array of reasons quoting specific spans from the input that justify the verdict, a recommended_action for the calling agent, and an optional Ed25519-signed VerityLayer receipt for audit/verification purposes.","failureModes":["Content exceeds 2000-character maxLength limit — request rejected with validation error","Ambiguous or heavily obfuscated content may return 'uncertain' verdict with partial reasons","Missing required fields (content) returns a 400-level schema validation error","Signing not configured returns null receipt even on successful scan","Context field itself may be adversarial — treated as a hint only, never trusted as authoritative"],"whenToPreferThis":"Choose this endpoint when your AI agent is about to consume externally-sourced text (web pages, emails, retrieved documents, tool outputs, user-supplied strings) and you need a fail-closed, per-call security gate before that content enters the agent's context window. Especially valuable in agentic pipelines with tool use, RAG retrieval, or any untrusted input channel. Prefer this over generic content moderation APIs when the threat model is specifically prompt injection and agent manipulation rather than hate speech or NSFW content.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:53:15.549Z","isFirstParty":false}