> For the complete documentation index, see [llms.txt](https://ai.ortusbooks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ai.ortusbooks.com/main-components/middleware/input-sanitizer.md).

# InputSanitizerMiddleware

Heuristic prompt-injection scanning and unicode hygiene for inbound content and tool results

Class: `bxModules.bxai.models.middleware.security.InputSanitizerMiddleware`

Scans inbound user content and optional tool results for prompt-injection indicators. Applies unicode normalization and invisible-character stripping before model execution.

## Features

* Scans user-role content before LLM call
* Optional scan of tool and MCP results in `wrapToolCall`
* Unicode hygiene via normalization and zero-width stripping
* Actions: `block`, `strip`, `flag`, `log`
* Findings can be stamped to `chatRequest.providerOptions.securityFindings`

## Constructor

```javascript
middleware = new bxModules.bxai.models.middleware.security.InputSanitizerMiddleware(
    action          : "flag",
    detectors       : [],
    customPatterns  : [],
    normalizeUnicode: true,
    stripZeroWidth  : true,
    scanToolResults : true
)
```

## Configuration

| Option             | Type    | Default  | Description                                      |
| ------------------ | ------- | -------- | ------------------------------------------------ |
| `action`           | string  | `"flag"` | Handling mode: `block`, `strip`, `flag`, `log`   |
| `detectors`        | array   | `[]`     | Detector names to run; empty means all built-ins |
| `customPatterns`   | array   | `[]`     | Additional patterns: `[ { name, regex } ]`       |
| `normalizeUnicode` | boolean | `true`   | Apply NFKC normalization                         |
| `stripZeroWidth`   | boolean | `true`   | Remove zero-width and invisible characters       |
| `scanToolResults`  | boolean | `true`   | Scan tool result strings for indirect injection  |

## Hooks Used

* `beforeLLMCall`
* `wrapToolCall`

## Action Semantics

* `block`: throws `BXAI.SecurityViolation` on findings before LLM call; tool-result findings return blocked marker text
* `strip`: removes matched fragments and continues
* `flag`: keeps content, stamps findings in provider options, logs warnings
* `log`: logs warnings only

## Example

```javascript
agent = aiAgent(
    middleware: [
        new bxModules.bxai.models.middleware.security.InputSanitizerMiddleware(
            action        : "block",
            detectors     : [ "instructionOverride", "jailbreak" ],
            customPatterns: [ { name: "internalCodes", regex: "(?i)PROJ-\\d{4}-SECRET" } ]
        )
    ]
)
```

## Notes

* Invalid actions throw `InvalidAction` during construction.
* Message content is mutated in place, including multipart text content sections.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ai.ortusbooks.com/main-components/middleware/input-sanitizer.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
