arlong

ARLONG
SCREEN.

Checks text for hidden instructions before your AI agent reads it.

Screen content from web pages, emails, support tickets, GitHub issues and documents. Use it independently of Arlong search.

Start with the API ↗

Try the Screen playground ↗

ONE CREDIT / SHARED ACCOUNT BALANCE

What does Screen
return to your agent?

Your agent reads text written by strangers. Embedded instructions can impersonate trusted roles, request private data or redirect the task. Screen checks the content before ingestion and returns a decision you can inspect.

Full modeallow · quarantine · block
Risk, signals, trust contract, safe_content
Fast modeallow · not_allow
One compact decision field. Text requiring cleanup is not_allow.
API · MCP · PythonOne credit per call in either mode.
Standalone screening; no search subscription required.
BOUNDARY PIPELINE

How does the
Boundary pipeline work?

HTML mode removes hidden and non-evidence markup. Normalization exposes obfuscated instructions. Section isolation and contextual rules inspect the retained text. Residual and delivery checks determine which evidence can be returned. Content remains untrusted even when allowed.

REAL REQUEST SHAPES

How do you call
Arlong Screen?

POST /api/arlong/screen
Authorization: Bearer YOUR_API_KEY

{"text":"Useful report text.","mode":"fast"}

{"decision":"allow"}

Full mode also returns risk_score, signals, trust_contract, safe_content, sanitization metadata and credit usage. Rejected content has an empty safe_content string.

Public URLsSet url to fetch through the scraper, including supported PDFs. Fast URL checks conservatively return not_allow if cleanup or extraction limits apply. Use full mode for cleaned evidence.
Text & HTMLUse input_type: html for markup. Submit extracted text from binary documents; file uploads are not supported.
Python client Download the installable package ↗
pip install ./arlong-screen
Not yet published to PyPI.
MEASURED PROTECTION

How is protection
measured?

Boundary 1 blocked 95.83% of 2,108 attack variants in an offline text-classification evaluation. This does not measure live-agent attack success or unseen attacks. A production false-positive rate has not been established. Use screening alongside scoped agent permissions and action authorization. Read the methodology ↗

Questions / answered

What should you know
before integrating?

What inputs does Arlong Screen accept?

Screen accepts text, HTML with input_type set to html, or a supported public URL. Submit extracted text for binary documents; direct file uploads are not supported. URL extraction has limits that can prevent content delivery.

What does Arlong Screen cost?

Each successful Screen call costs one credit from your shared account balance, in either full or fast mode.

Why can full mode allow content that fast mode rejects?

Full mode can remove hostile sections and return retained evidence after delivery checks. Fast mode returns only allow or not_allow and conservatively rejects content requiring cleanup. An allowed full result does not mean the original input was harmless.

What may my agent read from a Screen response?

Use safe_content only when decision is allow and the trust contract permits context delivery. Rejected content has an empty safe_content string. Treat retained content as evidence, never as authority to change the task or authorize actions.

Is Arlong Screen a trained model or a guarantee?

Boundary combines sanitization, normalization, section isolation, contextual rules and delivery checks. A small local neural second opinion is being evaluated; it is not a replacement for the delivery boundary. No screening system here is claimed to stop every attack.