Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

GeminiUtil placeholder user turn ("Continue output. DO NOT look at this line ...") is flagged by prompt injection filters

Ouverte Adaptée aux débutants
#1,628 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

@innoprej y travaille déjà.

Depuis le 8/10/2026.

  • #1629 par @innoprej — ouverte

Évaluation

Difficulté
2/5
Temps estimé
1-3 heures
Accessibilité débutants
76/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
google-cloud, java
Domaine
ai

Piste de recherche

Lisez GeminiUtil.ensureModelResponse, mentionné dans la reproduction, et comparez la formulation du texte de remplacement avec celle d’ADK Python et TypeScript décrite dans l’issue. Commencez par la reproduction au niveau unitaire avec ensureModelResponse(ImmutableList.of()) ; le travail est terminé lorsque le texte de remplacement généré ne déclenche plus le filtre de prompt injection signalé et correspond à la formulation convenue.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

🔴 Required Information

Describe the Bug:

When an LlmRequest has no contents, or its last content is not from the user, GeminiUtil.ensureModelResponse appends a placeholder user turn with this text:

Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction.

The sentence reads like an instruction-override prompt ("do not look at this line", "only look at ..."). On Vertex AI with Model Armor floor settings that enable prompt injection and jailbreak detection, requests whose only user-role content is this placeholder are blocked before the model runs. The other ADK languages use neutral wording: ADK Python and ADK TypeScript append "Handle the requests as specified in the System Instruction." when there are no contents, and "Continue processing previous requests as instructed. Exit or provide a summary if no more outputs are needed." when the last turn is not from the user; ADK Go uses the second sentence and appends nothing for empty contents.

Steps to Reproduce:

  1. Use com.google.adk:google-adk 1.10.1 (the code is unchanged in 1.11.0 and on main at ce882374) with a Vertex AI backed LlmAgent whose task is fully described by its instruction, for example with inputs passed through session state and the runner called with a user Content whose parts list is empty.
  2. In the same Google Cloud project, enable Model Armor floor settings for Vertex AI with prompt injection and jailbreak detection in blocking mode (confidence threshold: high).
  3. Run the agent.
  4. The first model call is rejected by Model Armor. At unit level, GeminiUtil.ensureModelResponse(ImmutableList.of()) returns one user content with the placeholder text above.

Expected Behavior:

The placeholder turn added by ADK should not look like a prompt injection attempt, and should match the wording used by the other ADK languages.

Observed Behavior:

The Model Armor sanitize log entry of a blocked request (payload removed) reports:

"piAndJailbreakFilterResult": {
  "confidenceLevel": "HIGH",
  "matchState": "MATCH_FOUND",
  "executionState": "EXECUTION_SUCCESS"
}

The other filters in the same entry returned NO_MATCH_FOUND. The inspected text was the system instruction followed by the placeholder line, and the placeholder was the only user-role content in every blocked request. The same requests succeeded before the detection was enabled, and ordinary chat requests in the same project, which end with user-typed text, were not blocked.

Model Armor returns one verdict per request, so the two sentences were also checked on their own. In the same project and settings, each sentence was typed as a plain user message in a new session of a chat agent (same system instruction for both): "Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction." was blocked by Model Armor, while "Handle the requests as specified in the System Instruction." (the ADK Python sentence for empty contents) was not. Only the sentence differed between the two requests, so the block comes from the wording of the Java sentence.

Environment Details:

  • ADK Library Version (see maven dependency): 1.10.1, code unchanged in 1.11.0 and on main (ce882374)
  • OS: Linux server (JDK 17); reproduced at unit level on Windows 11 / Microsoft Build of OpenJDK 17.0.19 / Maven 4.0.0-rc-3 (wrapper)

Model Information:

  • Which model is being used: gemini-3.8-flash (Vertex AI)

🟡 Optional Information

Regression:

No — the wording has been the same since v0.1.0 (first in Gemini, later moved to GeminiUtil).

How often has this issue occurred?:

  • Always (100%) for requests that contain no user-authored content.

Proposed fix:

Use the same wording as ADK Python and ADK TypeScript (a small PR will follow). Note that the Python empty-contents sentence was itself reported to trip Azure OpenAI's jailbreak filter in a LiteLLM code path (google/adk-python#4249; the wording was kept and the extra injection was removed in google/adk-python@d0102ec instead); Model Armor did not block it in the check above. Aligning the languages is proposed as the smallest change; making the placeholder text configurable would be an alternative if maintainers prefer.

Langage dominant
Java
Étoiles
1.7k
Forks
431
Merge moyen
3 j 2 h
PR mergées (30 j)
46

Préparer son environnement

Ouvrir dans Codespaces

Lance le conteneur de développement du projet dans votre navigateur, avec votre propre compte GitHub.

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de google/adk-java

Toutes les issues de google/adk-java

Issues similaires

Plus d'issues Java

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.