Scanners inspect one entry at a time and return a ScanOutcome with a risk score, rationale, and optional match spans. The pipeline adds each scanner’s configured severity and action to form a finding. Only BLOCK findings affect the aggregate verdict; other findings remain visible for review.
Every scanner accepts severity, action, and content_types, although their defaults differ. content_types: null accepts every entry type. An incompatible scanner is skipped and recorded rather than executed.
| Reference | Primary use | Default action |
|---|---|---|
Detect protected marker tokens. |
|
|
Find hidden Unicode instructions. |
|
|
Match suspicious patterns and code-oriented keywords. |
|
|
Detect regex-based personal-data patterns. |
|
|
Detect English NLP entities. |
|
|
Detect pattern-based injection attempts. |
|
|
Classify injection with an optional local model. |
|
|
Detect credentials and high-entropy values. |
|
|
Apply suspicious-URL heuristics. |
|
|
Require URLs to match approved patterns. |
|
|
Detect HTML and script injection vectors. |
|
Run preprocessors before scanners when text may use encoding or whitespace to hide its content. See Configuration for scanner records and Gate behavior for verdict calculation.