Pages
Policy Config — Output Validation
Source: c65 policy-definitions.md P13 — detector-list shape
‹ Policy Catalog
Output Validation
RoadmapAgent output is checked before it reaches downstream tools — what the model says becomes what the system does.
Input & Output Integrity
medium
P13Satisfies
OWASP LLM
OWASP ASI
EU AI Act
Underlying control— show
content: role = "assistant" and severity in (high, medium)edit as custom control →Output detectors
Detectors toggle individually; hit counts are the last 24h.
Output detectors
high
1 hitcredentials reflected back in outputmedium
3 hitsdestructive shell patternslow
5 hitsExceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| No exceptions — the policy applies everywhere. | ||||
Remediation shown on findings: Gate the consuming tool on validation; review the flagged output.