L1 Rule Catalog¶
These are the stable rule IDs accepted by execution-gate rules. Missing IDs inherit the shared Rust/Python/API defaults below. Model gates such as native:pii, native:dlp, native:injection_l1, and native:threat_l1 control complete producers; rule gates control individual entries below.
PII rules (39)¶
All PII rules are eligible by default when PII L1 is enabled.
| Rule ID | Result entity group | Extra validator |
|---|---|---|
pii_email |
EMAIL |
no |
pii_ipv4 |
IP_ADDRESS |
yes |
pii_ipv6_full |
IP_ADDRESS |
yes |
pii_ipv6_compressed |
IP_ADDRESS |
yes |
pii_ipv6_loopback |
IP_ADDRESS |
yes |
pii_phone_international |
PHONE |
yes |
pii_phone_de |
PHONE |
yes |
pii_phone_de_national_context |
PHONE |
yes |
pii_phone_us |
PHONE |
yes |
pii_mac_address |
MAC_ADDRESS |
yes |
pii_iban_de |
IBAN |
yes |
pii_iban_generic |
IBAN |
yes |
pii_credit_card |
CREDITCARD |
yes |
pii_credit_card_cvv |
CREDITCARD_CVV |
yes |
pii_credit_card_expiry |
CREDITCARD_EXPIRY |
yes |
pii_swift_bic_context |
SWIFT_CODE |
yes |
pii_employee_id |
EMPLOYEE_ID |
yes |
pii_employee_id_ocr_field |
EMPLOYEE_ID |
yes |
pii_employee_id_prefixed |
EMPLOYEE_ID |
yes |
pii_customer_id |
CUSTOMER_ID |
yes |
pii_patient_id |
PATIENT_ID |
yes |
pii_student_id |
STUDENT_ID |
yes |
pii_applicant_id |
APPLICANT_ID |
yes |
pii_username |
USERNAME |
yes |
pii_date_of_birth |
DOB |
yes |
pii_date_of_birth_written_day_first |
DOB |
yes |
pii_date_of_birth_written_month_first |
DOB |
yes |
pii_financial_account_number |
FINANCIAL_ACCOUNT_NUMBER |
yes |
pii_steuer_id_de |
STEUERID |
yes |
pii_steuernummer_de |
TAX_NUMBER_DE |
yes |
pii_rentenversicherung_de |
SOCIALID |
yes |
pii_health_insurance_number_de |
HEALTH_INSURANCE_NUMBER |
yes |
pii_physician_number_lanr_de |
PHYSICIAN_NUMBER_LANR |
yes |
pii_passport_number_de |
PASSPORT_NUMBER |
yes |
pii_identity_card_number_de |
IDENTITY_CARD_NUMBER |
yes |
pii_driver_license_number_de |
DRIVER_LICENSE_NUMBER |
yes |
pii_kfz_kennzeichen_de |
LICENSEPLATE |
no |
pii_ssn_us |
SSN |
yes |
pii_ni_uk |
NATIONALID |
yes |
DLP regex rules (59)¶
Rust, Python, and the Ark API enable only credential/secret entity groups by default. Set a rule to true to opt into a broader family. Low-level detector evaluate() calls bypass gateway execution gates and evaluate the full detector inventory.
| Rule ID | Result entity group | Extra validator | Default |
|---|---|---|---|
dlp_anthropic_key |
API_KEY |
yes | on |
dlp_openai_key |
API_KEY |
no | on |
dlp_openai_legacy |
API_KEY |
no | on |
dlp_openai_svc |
API_KEY |
no | on |
dlp_huggingface |
API_KEY |
no | on |
dlp_groq_key |
API_KEY |
no | on |
dlp_xai_key |
API_KEY |
no | on |
dlp_replicate |
API_KEY |
no | on |
dlp_aws_access_key |
CLOUD_KEY |
no | on |
dlp_aws_secret_key |
CLOUD_KEY |
no | on |
dlp_google_api_key |
CLOUD_KEY |
no | on |
dlp_google_oauth_token |
CLOUD_KEY |
no | on |
dlp_gcp_client_secret |
CLOUD_KEY |
no | on |
dlp_github_token |
SECRET_TOKEN |
no | on |
dlp_github_pat |
SECRET_TOKEN |
no | on |
dlp_gitlab_pat |
SECRET_TOKEN |
no | on |
dlp_npm_token |
SECRET_TOKEN |
no | on |
dlp_stripe_key |
PAYMENT_KEY |
no | on |
dlp_stripe_webhook |
PAYMENT_KEY |
no | on |
dlp_slack_token |
SECRET_TOKEN |
no | on |
dlp_discord_token |
SECRET_TOKEN |
no | on |
dlp_eth_private_key |
CRYPTO_KEY |
no | on |
dlp_btc_wif |
CRYPTO_KEY |
no | on |
dlp_private_key_block |
PRIVATE_KEY |
no | on |
dlp_private_key_header |
PRIVATE_KEY |
no | on |
dlp_jwt_token |
SECRET_TOKEN |
no | on |
dlp_credential_in_url |
CREDENTIAL |
yes | on |
dlp_env_var_secret |
CREDENTIAL |
yes | on |
dlp_password_assignment |
CREDENTIAL |
yes | on |
dlp_generic_credential_assignment |
CREDENTIAL |
yes | on |
dlp_bearer_token |
SECRET_TOKEN |
yes | on |
dlp_basic_auth |
CREDENTIAL |
yes | on |
dlp_signed_url_signature |
CREDENTIAL |
yes | on |
dlp_session_cookie |
CREDENTIAL |
yes | on |
dlp_csrf_token |
SECRET_TOKEN |
yes | on |
dlp_password_hash |
PASSWORD_HASH |
yes | on |
dlp_url_userinfo_password |
CREDENTIAL |
yes | on |
dlp_de_vat_id |
dlp.de.vat_id |
no | off |
dlp_de_commercial_register_number |
dlp.de.commercial_register_number |
yes | off |
dlp_de_facility_number_bsnr |
dlp.de.facility_number_bsnr |
no | off |
dlp_record_case_id |
dlp.record.case_id |
yes | off |
dlp_record_contract_id |
dlp.record.contract_id |
yes | off |
dlp_record_claim_id |
dlp.record.claim_id |
yes | off |
dlp_record_order_id |
dlp.record.order_id |
yes | off |
dlp_record_invoice_id |
dlp.record.invoice_id |
yes | off |
dlp_project_id |
dlp.project_id |
yes | off |
dlp_organization_id |
dlp.organization_id |
yes | off |
dlp_internal_business_metric |
dlp.internal.business_metric |
no | off |
dlp_database_dump_insert |
dlp.content.database_dump |
no | off |
dlp_source_code_fence |
dlp.content.source_code |
no | off |
dlp_source_code_statement |
dlp.content.source_code |
no | off |
dlp_source_code_python_rust_assignment |
dlp.content.source_code |
yes | off |
dlp_source_code_declaration |
dlp.content.source_code |
no | off |
dlp_source_code_import |
dlp.content.source_code |
no | off |
dlp_sql_statement |
dlp.content.sql |
yes | off |
dlp_sql_multiline_statement |
dlp.content.sql |
no | off |
dlp_database_dump_header |
dlp.content.database_dump |
no | off |
dlp_stacktrace_block |
dlp.content.system_log |
no | off |
dlp_structured_system_log |
dlp.content.system_log |
no | off |
DLP relationship rules (5)¶
These rules use the shared source-bound component contract and emit finding spans. Their evidence includes action/target relations or MCP tool/argument components.
| Rule ID | Model gate | Default |
|---|---|---|
dlp_sensitive_material |
native:sensitive_material |
on |
dlp_secret_transfer |
native:secret_transfer |
on |
dlp_mcp_runtime_risk |
native:mcp_runtime_risk |
off |
dlp_mcp_policy |
native:mcp_policy |
off |
dlp_destructive_operation |
native:destructive_operation |
off |
Injection rules (57)¶
Injection rule IDs gate versioned catalog entries, native evidence producers, and the structural producer. Several source rules can intentionally share one canonical ID; the table lists each effective gate once.
| Rule ID | Family | Description | Source |
|---|---|---|---|
ark.injection.agentic.control_abuse |
agentic_control_abuse |
Native producer gate for native:agentic_control_abuse. | ark-native-injection-71ff48e |
ark.injection.authority.claim |
authority_escalation |
Claim to be developer/admin | prompt-armor-complete-95e532e |
ark.injection.authority.escalation |
authority_escalation |
Native producer gate for native:authority_escalation. | ark-native-injection-71ff48e |
ark.injection.authority.fake_system_asset_transfer |
authority_escalation |
Uses a fake system or administrator authority marker to mandate a concrete crypto-asset transfer | source-derived-coverage-0.1.6 |
ark.injection.boundary.delimited_replacement_action |
instruction_boundary |
Uses a synthetic delimiter boundary before a replacement instruction and action | source-derived-p0-0.1.6 |
ark.injection.boundary.delimiter |
instruction_boundary |
Native producer gate for native:instruction_boundary. | ark-native-injection-71ff48e |
ark.injection.boundary.fake_system |
instruction_boundary |
Fake system prompt injection | prompt-armor-complete-95e532e |
ark.injection.boundary.persona_directive |
instruction_boundary |
Forged system-role boundary followed by an unsafe persona directive | source-derived-coverage-0.1.6 |
ark.injection.covert.execution |
covert_instruction |
Native producer gate for native:covert_instruction. | ark-native-injection-71ff48e |
ark.injection.cross_tool.override_action |
cross_tool_instruction |
Native producer gate for native:cross_tool_instruction. | ark-native-injection-71ff48e |
ark.injection.cross_tool.override_then_call |
cross_tool_instruction |
Overrides the user or prior instructions in order to invoke another tool | source-derived-coverage-0.1.6 |
ark.injection.escalation.multi_turn |
multi_turn_escalation |
Native producer gate for native:multi_turn_escalation. | ark-native-injection-71ff48e |
ark.injection.escalation.prior_bypass_agreement |
multi_turn_escalation |
Claims prior agreement to bypass active safety restrictions | source-derived-coverage-0.1.6 |
ark.injection.exfil.external_sink |
cross_tool_instruction |
Send data to external URL/email | prompt-armor-complete-95e532e |
ark.injection.exfil.sensitive_path_external_sink_audited |
cross_tool_instruction |
Reads a sensitive credential path and transfers it to an explicit external network destination | source-derived-p0-0.1.6 |
ark.injection.exfil.sensitive_path_to_sink |
cross_tool_instruction |
Reads a sensitive credential path and directs its contents to an output or transfer sink | source-derived-p0-0.1.6 |
ark.injection.guardrail.disable_directive |
guardrail_tamper |
Imperative bypass of explicit safety controls | source-derived-coverage-0.1.6 |
ark.injection.guardrail.tamper |
guardrail_tamper |
Native producer gate for native:guardrail_tamper. | ark-native-injection-71ff48e |
ark.injection.identity.reassign |
jailbreak_framing |
Identity reassignment | prompt-armor-complete-95e532e |
ark.injection.jailbreak.dual_response |
jailbreak_framing |
Dual response mode (classic DAN pattern) | prompt-armor-complete-95e532e |
ark.injection.jailbreak.framing |
jailbreak_framing |
Native producer gate for native:jailbreak_framing. | ark-native-injection-71ff48e |
ark.injection.jailbreak.game_framing |
jailbreak_framing |
Game-based jailbreak opening | prompt-armor-complete-95e532e |
ark.injection.jailbreak.named_mode |
jailbreak_framing |
Known jailbreak persona names | prompt-armor-complete-95e532e |
ark.injection.jailbreak.remove_constraints |
jailbreak_framing |
Bypass restrictions/safety | prompt-armor-complete-95e532e |
ark.injection.leak.hidden_instructions |
instruction_leak |
Native producer gate for native:instruction_leak. | ark-native-injection-71ff48e |
ark.injection.leak.own_prompt |
instruction_leak |
Disclosure of the assistant own prompt | source-derived-coverage-0.1.6 |
ark.injection.leak.system_instructions |
instruction_leak |
Request to reveal system prompt | prompt-armor-complete-95e532e |
ark.injection.leak.system_prompt_extraction |
instruction_leak |
Directly requests disclosure of the assistant's system or initialization instructions | source-derived-coverage-0.1.6 |
ark.injection.obfuscation.binary_smuggling |
binary_smuggling |
Native producer gate for native:binary_smuggling. | ark-native-injection-71ff48e |
ark.injection.obfuscation.decode_for_instructions |
encoded_instruction |
Directs decoding an opaque message specifically to obtain instructions | source-derived-coverage-0.1.6 |
ark.injection.obfuscation.decode_request |
encoded_instruction |
Encoded message decode request | prompt-armor-complete-95e532e |
ark.injection.obfuscation.decode_then_execute |
encoded_instruction |
Directs the model to decode an encoded payload and execute or follow it | source-derived-p0-0.1.6 |
ark.injection.obfuscation.encoded_instruction |
encoded_instruction |
Native producer gate for native:encoded_instruction. | ark-native-injection-71ff48e |
ark.injection.obfuscation.encoded_instruction_payload |
encoded_instruction |
Requests decoding of a supplied payload containing an instruction override or prompt disclosure | source-derived-coverage-0.1.6 |
ark.injection.obfuscation.escaped_instruction_payload |
encoded_instruction |
Requests decoding a Unicode-escaped instruction override or prompt disclosure | source-derived-coverage-0.1.6 |
ark.injection.obfuscation.hidden_html |
hidden_html_instruction |
Native producer gate for native:hidden_html_instruction. | ark-native-injection-71ff48e |
ark.injection.obfuscation.steganographic |
encoded_instruction |
Acrostic/steganographic instruction | prompt-armor-complete-95e532e |
ark.injection.obfuscation.unicode_confusable |
unicode_confusable |
Native producer gate for native:unicode_confusable. | ark-native-injection-71ff48e |
ark.injection.obfuscation.zero_width |
zero_width_obfuscation |
Native producer gate for native:zero_width_obfuscation. | ark-native-injection-71ff48e |
ark.injection.output.forced_marker |
output_manipulation |
Native producer gate for native:output_manipulation. | ark-native-injection-71ff48e |
ark.injection.output.ignore_then_fixed_output |
output_manipulation |
Overrides surrounding instructions and restricts the response to attacker-chosen output | source-derived-coverage-0.1.6 |
ark.injection.override.authority_issued_replacement |
instruction_override |
Claims that an authority issued replacement instructions and demands an action | source-derived-p0-0.1.6 |
ark.injection.override.discard_prior |
instruction_override |
Ignore previous instructions pattern | prompt-armor-complete-95e532e |
ark.injection.override.ethical_parameters |
instruction_override |
Reset existing ethical constraints | source-derived-coverage-0.1.6 |
ark.injection.override.hierarchy |
instruction_override |
Native producer gate for native:instruction_override. | ark-native-injection-71ff48e |
ark.injection.override.hierarchy_then_direct_action |
instruction_override |
Discards an instruction-hierarchy constraint and immediately requests a replacement action | source-derived-coverage-0.1.6 |
ark.injection.override.obfuscated_discard |
instruction_override |
Ignore what I said before (incl. typos) | prompt-armor-complete-95e532e |
ark.injection.override.prior_reference |
instruction_override |
Override an explicit prior-context reference | source-derived-coverage-0.1.6 |
ark.injection.override.replacement_directive |
instruction_override |
New instructions declaration | prompt-armor-complete-95e532e |
ark.injection.skillspector.anti_refusal |
jailbreak_framing |
Explicit bilingual instruction-boundary violation: anti_refusal | ark-skillspector-derived-0.1.7 |
ark.injection.skillspector.memory_reset |
instruction_override |
Explicit bilingual instruction-boundary violation: memory_reset | ark-skillspector-derived-0.1.7 |
ark.injection.skillspector.persistent_override |
multi_turn_escalation |
Explicit bilingual instruction-boundary violation: persistent_override | ark-skillspector-derived-0.1.7 |
ark.injection.skillspector.policy_nullification |
guardrail_tamper |
Explicit bilingual instruction-boundary violation: policy_nullification | ark-skillspector-derived-0.1.7 |
ark.injection.skillspector.unconditional_compliance |
jailbreak_framing |
Explicit bilingual instruction-boundary violation: unconditional_compliance | ark-skillspector-derived-0.1.7 |
ark.injection.structure.override_sensitive_disclosure |
instruction_override |
Structural override plus sensitive-disclosure relationship. | native structural producer |
ark.injection.tool_call.injected |
tool_call_injection |
Native producer gate for native:tool_call_injection. | ark-native-injection-71ff48e |
ark.injection.tool_output.override |
tool_output_instruction |
Native producer gate for native:tool_output_instruction. | ark-native-injection-71ff48e |
Threat rules (30)¶
Enabled by default when Threat L1 is configured. Matches report risky operations, not proof of malicious intent. See Threat L1 for context and coverage limits.
| Rule ID | Threat class | SkillSpector reference groups |
|---|---|---|
ark.threat.remote_execution |
tool_abuse |
SC2, TM2 |
ark.threat.remote_execution_instruction |
tool_abuse |
SC2, TM2 |
ark.threat.decoded_execution |
tool_abuse |
SC3 |
ark.threat.decoded_shell_execution |
tool_abuse |
SC3, TM2 |
ark.threat.credential_harvesting |
secrets_access |
PE3, AS1, E3 |
ark.threat.credential_file_access |
secrets_access |
PE3, AS1 |
ark.threat.secret_exfiltration |
exfiltration_attempt |
E1, E3, E5 |
ark.threat.credential_file_upload |
exfiltration_attempt |
E3, E5 |
ark.threat.environment_exfiltration |
exfiltration_attempt |
E2 |
ark.threat.docker_socket |
tool_abuse |
PE4 |
ark.threat.privileged_container |
tool_abuse |
PE5, TM4 |
ark.threat.host_root_mount |
tool_abuse |
PE5 |
ark.threat.persistence_payload |
harmful_behavior |
RA2 |
ark.threat.agent_guard_removal |
harmful_behavior |
RA1, AS1 |
ark.threat.security_disable |
tool_abuse |
TM3, SC7 |
ark.threat.untrusted_deserialization |
tool_abuse |
DS1, DS2, DS3, AST10 |
ark.threat.untrusted_output_execution |
tool_abuse |
OH1, OH2 |
ark.threat.ssrf_metadata |
secrets_access |
SSRF1 |
ark.threat.session_exfiltration |
exfiltration_attempt |
E4, P3 |
ark.threat.environment_post |
exfiltration_attempt |
E2 |
ark.threat.agent_config_exfiltration |
exfiltration_attempt |
AS1, AS2, AS3 |
ark.threat.kubernetes_privileged_json |
tool_abuse |
TM4, PE5 |
ark.threat.kubernetes_privileged_yaml |
tool_abuse |
TM4, PE5 |
ark.threat.unsafe_tls_code |
tool_abuse |
TM3, SC7 |
ark.threat.unsafe_shell_input |
tool_abuse |
TM1 |
ark.threat.dynamic_ssrf |
tool_abuse |
SSRF3, TT |
ark.threat.root_destruction |
harmful_behavior |
TM1 |
ark.threat.unauthorized_autonomy |
tool_abuse |
EA2, EA3 |
ark.threat.harmful_intent |
harmful_behavior |
P5 |
ark.threat.secret_source_transfer |
exfiltration_attempt |
E3, E5 |