Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automatically injected recall/reflect text is currently raw text under an instruction-like preamble. Frame that evidence with a fixed JSON shape, escape wrapper/fence characters inside its strings, and bound the encoded block to 16,000 characters without breaking JSON. The default preamble identifies the block as untrusted evidence; an explicitly configured recall_prompt_preamble still wins. Manual tool-result formatting is unchanged.
Related existing public report: vectorize-io#5424; prior reference implementation vectorize-io#4676 by @yingliang-zhang. This is defense in depth, not a claim of model-level protection or a new vulnerability disclosure. The maintained fork carries the feature under upstream's external-PR policy.
Validation: four deterministic cases cover escaped wrappers/fences, Unicode round trips, valid bounded JSON for escape-heavy input and custom-preamble preservation. This branch passed 70 provider tests (two host probes skipped without host settings); the combined candidate passed all 81. Full repository lint passed on the combined candidate. Exact-head fork CI remains required.
A separate hs_llm_core test uses the actual shared formatter/preamble, a real answer model and the existing independent LLM judge. It has NOT been executed in this credential-free rehearsal: structural tests do not demonstrate that any particular model follows the boundary. Semantic acceptance remains a separate gate before adoption.
Base: integration/memory-20261006 at e211b2b. No deployment, bank changes or paid model calls.
Exact-head CI update: all eight Memory fork CI jobs passed in run 37880535713. This remains draft until the opt-in real-LLM/independent-judge acceptance test is executed and documented. No credentials were used for CI.