Skip to content

L1 Rule Catalog

These are the stable rule IDs accepted by execution-gate rules. Missing IDs inherit the shared Rust/Python/API defaults below. Model gates such as native:pii, native:dlp, native:injection_l1, and native:threat_l1 control complete producers; rule gates control individual entries below.

PII rules (39)

All PII rules are eligible by default when PII L1 is enabled.

Rule ID Result entity group Extra validator
pii_email EMAIL no
pii_ipv4 IP_ADDRESS yes
pii_ipv6_full IP_ADDRESS yes
pii_ipv6_compressed IP_ADDRESS yes
pii_ipv6_loopback IP_ADDRESS yes
pii_phone_international PHONE yes
pii_phone_de PHONE yes
pii_phone_de_national_context PHONE yes
pii_phone_us PHONE yes
pii_mac_address MAC_ADDRESS yes
pii_iban_de IBAN yes
pii_iban_generic IBAN yes
pii_credit_card CREDITCARD yes
pii_credit_card_cvv CREDITCARD_CVV yes
pii_credit_card_expiry CREDITCARD_EXPIRY yes
pii_swift_bic_context SWIFT_CODE yes
pii_employee_id EMPLOYEE_ID yes
pii_employee_id_ocr_field EMPLOYEE_ID yes
pii_employee_id_prefixed EMPLOYEE_ID yes
pii_customer_id CUSTOMER_ID yes
pii_patient_id PATIENT_ID yes
pii_student_id STUDENT_ID yes
pii_applicant_id APPLICANT_ID yes
pii_username USERNAME yes
pii_date_of_birth DOB yes
pii_date_of_birth_written_day_first DOB yes
pii_date_of_birth_written_month_first DOB yes
pii_financial_account_number FINANCIAL_ACCOUNT_NUMBER yes
pii_steuer_id_de STEUERID yes
pii_steuernummer_de TAX_NUMBER_DE yes
pii_rentenversicherung_de SOCIALID yes
pii_health_insurance_number_de HEALTH_INSURANCE_NUMBER yes
pii_physician_number_lanr_de PHYSICIAN_NUMBER_LANR yes
pii_passport_number_de PASSPORT_NUMBER yes
pii_identity_card_number_de IDENTITY_CARD_NUMBER yes
pii_driver_license_number_de DRIVER_LICENSE_NUMBER yes
pii_kfz_kennzeichen_de LICENSEPLATE no
pii_ssn_us SSN yes
pii_ni_uk NATIONALID yes

DLP regex rules (59)

Rust, Python, and the Ark API enable only credential/secret entity groups by default. Set a rule to true to opt into a broader family. Low-level detector evaluate() calls bypass gateway execution gates and evaluate the full detector inventory.

Rule ID Result entity group Extra validator Default
dlp_anthropic_key API_KEY yes on
dlp_openai_key API_KEY no on
dlp_openai_legacy API_KEY no on
dlp_openai_svc API_KEY no on
dlp_huggingface API_KEY no on
dlp_groq_key API_KEY no on
dlp_xai_key API_KEY no on
dlp_replicate API_KEY no on
dlp_aws_access_key CLOUD_KEY no on
dlp_aws_secret_key CLOUD_KEY no on
dlp_google_api_key CLOUD_KEY no on
dlp_google_oauth_token CLOUD_KEY no on
dlp_gcp_client_secret CLOUD_KEY no on
dlp_github_token SECRET_TOKEN no on
dlp_github_pat SECRET_TOKEN no on
dlp_gitlab_pat SECRET_TOKEN no on
dlp_npm_token SECRET_TOKEN no on
dlp_stripe_key PAYMENT_KEY no on
dlp_stripe_webhook PAYMENT_KEY no on
dlp_slack_token SECRET_TOKEN no on
dlp_discord_token SECRET_TOKEN no on
dlp_eth_private_key CRYPTO_KEY no on
dlp_btc_wif CRYPTO_KEY no on
dlp_private_key_block PRIVATE_KEY no on
dlp_private_key_header PRIVATE_KEY no on
dlp_jwt_token SECRET_TOKEN no on
dlp_credential_in_url CREDENTIAL yes on
dlp_env_var_secret CREDENTIAL yes on
dlp_password_assignment CREDENTIAL yes on
dlp_generic_credential_assignment CREDENTIAL yes on
dlp_bearer_token SECRET_TOKEN yes on
dlp_basic_auth CREDENTIAL yes on
dlp_signed_url_signature CREDENTIAL yes on
dlp_session_cookie CREDENTIAL yes on
dlp_csrf_token SECRET_TOKEN yes on
dlp_password_hash PASSWORD_HASH yes on
dlp_url_userinfo_password CREDENTIAL yes on
dlp_de_vat_id dlp.de.vat_id no off
dlp_de_commercial_register_number dlp.de.commercial_register_number yes off
dlp_de_facility_number_bsnr dlp.de.facility_number_bsnr no off
dlp_record_case_id dlp.record.case_id yes off
dlp_record_contract_id dlp.record.contract_id yes off
dlp_record_claim_id dlp.record.claim_id yes off
dlp_record_order_id dlp.record.order_id yes off
dlp_record_invoice_id dlp.record.invoice_id yes off
dlp_project_id dlp.project_id yes off
dlp_organization_id dlp.organization_id yes off
dlp_internal_business_metric dlp.internal.business_metric no off
dlp_database_dump_insert dlp.content.database_dump no off
dlp_source_code_fence dlp.content.source_code no off
dlp_source_code_statement dlp.content.source_code no off
dlp_source_code_python_rust_assignment dlp.content.source_code yes off
dlp_source_code_declaration dlp.content.source_code no off
dlp_source_code_import dlp.content.source_code no off
dlp_sql_statement dlp.content.sql yes off
dlp_sql_multiline_statement dlp.content.sql no off
dlp_database_dump_header dlp.content.database_dump no off
dlp_stacktrace_block dlp.content.system_log no off
dlp_structured_system_log dlp.content.system_log no off

DLP relationship rules (5)

These rules use the shared source-bound component contract and emit finding spans. Their evidence includes action/target relations or MCP tool/argument components.

Rule ID Model gate Default
dlp_sensitive_material native:sensitive_material on
dlp_secret_transfer native:secret_transfer on
dlp_mcp_runtime_risk native:mcp_runtime_risk off
dlp_mcp_policy native:mcp_policy off
dlp_destructive_operation native:destructive_operation off

Injection rules (57)

Injection rule IDs gate versioned catalog entries, native evidence producers, and the structural producer. Several source rules can intentionally share one canonical ID; the table lists each effective gate once.

Rule ID Family Description Source
ark.injection.agentic.control_abuse agentic_control_abuse Native producer gate for native:agentic_control_abuse. ark-native-injection-71ff48e
ark.injection.authority.claim authority_escalation Claim to be developer/admin prompt-armor-complete-95e532e
ark.injection.authority.escalation authority_escalation Native producer gate for native:authority_escalation. ark-native-injection-71ff48e
ark.injection.authority.fake_system_asset_transfer authority_escalation Uses a fake system or administrator authority marker to mandate a concrete crypto-asset transfer source-derived-coverage-0.1.6
ark.injection.boundary.delimited_replacement_action instruction_boundary Uses a synthetic delimiter boundary before a replacement instruction and action source-derived-p0-0.1.6
ark.injection.boundary.delimiter instruction_boundary Native producer gate for native:instruction_boundary. ark-native-injection-71ff48e
ark.injection.boundary.fake_system instruction_boundary Fake system prompt injection prompt-armor-complete-95e532e
ark.injection.boundary.persona_directive instruction_boundary Forged system-role boundary followed by an unsafe persona directive source-derived-coverage-0.1.6
ark.injection.covert.execution covert_instruction Native producer gate for native:covert_instruction. ark-native-injection-71ff48e
ark.injection.cross_tool.override_action cross_tool_instruction Native producer gate for native:cross_tool_instruction. ark-native-injection-71ff48e
ark.injection.cross_tool.override_then_call cross_tool_instruction Overrides the user or prior instructions in order to invoke another tool source-derived-coverage-0.1.6
ark.injection.escalation.multi_turn multi_turn_escalation Native producer gate for native:multi_turn_escalation. ark-native-injection-71ff48e
ark.injection.escalation.prior_bypass_agreement multi_turn_escalation Claims prior agreement to bypass active safety restrictions source-derived-coverage-0.1.6
ark.injection.exfil.external_sink cross_tool_instruction Send data to external URL/email prompt-armor-complete-95e532e
ark.injection.exfil.sensitive_path_external_sink_audited cross_tool_instruction Reads a sensitive credential path and transfers it to an explicit external network destination source-derived-p0-0.1.6
ark.injection.exfil.sensitive_path_to_sink cross_tool_instruction Reads a sensitive credential path and directs its contents to an output or transfer sink source-derived-p0-0.1.6
ark.injection.guardrail.disable_directive guardrail_tamper Imperative bypass of explicit safety controls source-derived-coverage-0.1.6
ark.injection.guardrail.tamper guardrail_tamper Native producer gate for native:guardrail_tamper. ark-native-injection-71ff48e
ark.injection.identity.reassign jailbreak_framing Identity reassignment prompt-armor-complete-95e532e
ark.injection.jailbreak.dual_response jailbreak_framing Dual response mode (classic DAN pattern) prompt-armor-complete-95e532e
ark.injection.jailbreak.framing jailbreak_framing Native producer gate for native:jailbreak_framing. ark-native-injection-71ff48e
ark.injection.jailbreak.game_framing jailbreak_framing Game-based jailbreak opening prompt-armor-complete-95e532e
ark.injection.jailbreak.named_mode jailbreak_framing Known jailbreak persona names prompt-armor-complete-95e532e
ark.injection.jailbreak.remove_constraints jailbreak_framing Bypass restrictions/safety prompt-armor-complete-95e532e
ark.injection.leak.hidden_instructions instruction_leak Native producer gate for native:instruction_leak. ark-native-injection-71ff48e
ark.injection.leak.own_prompt instruction_leak Disclosure of the assistant own prompt source-derived-coverage-0.1.6
ark.injection.leak.system_instructions instruction_leak Request to reveal system prompt prompt-armor-complete-95e532e
ark.injection.leak.system_prompt_extraction instruction_leak Directly requests disclosure of the assistant's system or initialization instructions source-derived-coverage-0.1.6
ark.injection.obfuscation.binary_smuggling binary_smuggling Native producer gate for native:binary_smuggling. ark-native-injection-71ff48e
ark.injection.obfuscation.decode_for_instructions encoded_instruction Directs decoding an opaque message specifically to obtain instructions source-derived-coverage-0.1.6
ark.injection.obfuscation.decode_request encoded_instruction Encoded message decode request prompt-armor-complete-95e532e
ark.injection.obfuscation.decode_then_execute encoded_instruction Directs the model to decode an encoded payload and execute or follow it source-derived-p0-0.1.6
ark.injection.obfuscation.encoded_instruction encoded_instruction Native producer gate for native:encoded_instruction. ark-native-injection-71ff48e
ark.injection.obfuscation.encoded_instruction_payload encoded_instruction Requests decoding of a supplied payload containing an instruction override or prompt disclosure source-derived-coverage-0.1.6
ark.injection.obfuscation.escaped_instruction_payload encoded_instruction Requests decoding a Unicode-escaped instruction override or prompt disclosure source-derived-coverage-0.1.6
ark.injection.obfuscation.hidden_html hidden_html_instruction Native producer gate for native:hidden_html_instruction. ark-native-injection-71ff48e
ark.injection.obfuscation.steganographic encoded_instruction Acrostic/steganographic instruction prompt-armor-complete-95e532e
ark.injection.obfuscation.unicode_confusable unicode_confusable Native producer gate for native:unicode_confusable. ark-native-injection-71ff48e
ark.injection.obfuscation.zero_width zero_width_obfuscation Native producer gate for native:zero_width_obfuscation. ark-native-injection-71ff48e
ark.injection.output.forced_marker output_manipulation Native producer gate for native:output_manipulation. ark-native-injection-71ff48e
ark.injection.output.ignore_then_fixed_output output_manipulation Overrides surrounding instructions and restricts the response to attacker-chosen output source-derived-coverage-0.1.6
ark.injection.override.authority_issued_replacement instruction_override Claims that an authority issued replacement instructions and demands an action source-derived-p0-0.1.6
ark.injection.override.discard_prior instruction_override Ignore previous instructions pattern prompt-armor-complete-95e532e
ark.injection.override.ethical_parameters instruction_override Reset existing ethical constraints source-derived-coverage-0.1.6
ark.injection.override.hierarchy instruction_override Native producer gate for native:instruction_override. ark-native-injection-71ff48e
ark.injection.override.hierarchy_then_direct_action instruction_override Discards an instruction-hierarchy constraint and immediately requests a replacement action source-derived-coverage-0.1.6
ark.injection.override.obfuscated_discard instruction_override Ignore what I said before (incl. typos) prompt-armor-complete-95e532e
ark.injection.override.prior_reference instruction_override Override an explicit prior-context reference source-derived-coverage-0.1.6
ark.injection.override.replacement_directive instruction_override New instructions declaration prompt-armor-complete-95e532e
ark.injection.skillspector.anti_refusal jailbreak_framing Explicit bilingual instruction-boundary violation: anti_refusal ark-skillspector-derived-0.1.7
ark.injection.skillspector.memory_reset instruction_override Explicit bilingual instruction-boundary violation: memory_reset ark-skillspector-derived-0.1.7
ark.injection.skillspector.persistent_override multi_turn_escalation Explicit bilingual instruction-boundary violation: persistent_override ark-skillspector-derived-0.1.7
ark.injection.skillspector.policy_nullification guardrail_tamper Explicit bilingual instruction-boundary violation: policy_nullification ark-skillspector-derived-0.1.7
ark.injection.skillspector.unconditional_compliance jailbreak_framing Explicit bilingual instruction-boundary violation: unconditional_compliance ark-skillspector-derived-0.1.7
ark.injection.structure.override_sensitive_disclosure instruction_override Structural override plus sensitive-disclosure relationship. native structural producer
ark.injection.tool_call.injected tool_call_injection Native producer gate for native:tool_call_injection. ark-native-injection-71ff48e
ark.injection.tool_output.override tool_output_instruction Native producer gate for native:tool_output_instruction. ark-native-injection-71ff48e

Threat rules (30)

Enabled by default when Threat L1 is configured. Matches report risky operations, not proof of malicious intent. See Threat L1 for context and coverage limits.

Rule ID Threat class SkillSpector reference groups
ark.threat.remote_execution tool_abuse SC2, TM2
ark.threat.remote_execution_instruction tool_abuse SC2, TM2
ark.threat.decoded_execution tool_abuse SC3
ark.threat.decoded_shell_execution tool_abuse SC3, TM2
ark.threat.credential_harvesting secrets_access PE3, AS1, E3
ark.threat.credential_file_access secrets_access PE3, AS1
ark.threat.secret_exfiltration exfiltration_attempt E1, E3, E5
ark.threat.credential_file_upload exfiltration_attempt E3, E5
ark.threat.environment_exfiltration exfiltration_attempt E2
ark.threat.docker_socket tool_abuse PE4
ark.threat.privileged_container tool_abuse PE5, TM4
ark.threat.host_root_mount tool_abuse PE5
ark.threat.persistence_payload harmful_behavior RA2
ark.threat.agent_guard_removal harmful_behavior RA1, AS1
ark.threat.security_disable tool_abuse TM3, SC7
ark.threat.untrusted_deserialization tool_abuse DS1, DS2, DS3, AST10
ark.threat.untrusted_output_execution tool_abuse OH1, OH2
ark.threat.ssrf_metadata secrets_access SSRF1
ark.threat.session_exfiltration exfiltration_attempt E4, P3
ark.threat.environment_post exfiltration_attempt E2
ark.threat.agent_config_exfiltration exfiltration_attempt AS1, AS2, AS3
ark.threat.kubernetes_privileged_json tool_abuse TM4, PE5
ark.threat.kubernetes_privileged_yaml tool_abuse TM4, PE5
ark.threat.unsafe_tls_code tool_abuse TM3, SC7
ark.threat.unsafe_shell_input tool_abuse TM1
ark.threat.dynamic_ssrf tool_abuse SSRF3, TT
ark.threat.root_destruction harmful_behavior TM1
ark.threat.unauthorized_autonomy tool_abuse EA2, EA3
ark.threat.harmful_intent harmful_behavior P5
ark.threat.secret_source_transfer exfiltration_attempt E3, E5