GeminiUtil placeholder user turn ("Continue output. DO NOT look at this line ...") is flagged by prompt injection filters
维护者通常 1 天内回复
评估
调研方向
阅读复现步骤中提到的 GeminiUtil.ensureModelResponse,并将其占位文本的措辞与 issue 中描述的 ADK Python 和 TypeScript 措辞进行比较。先使用 ensureModelResponse(ImmutableList.of()) 进行单元级复现;当生成的占位文本不再触发报告中提到的 prompt injection 过滤器,并且与商定的措辞一致时,即为完成。
由索引模型根据 Issue 内容生成。
描述
🔴 Required Information
Describe the Bug:
When an LlmRequest has no contents, or its last content is not from the user, GeminiUtil.ensureModelResponse appends a placeholder user turn with this text:
Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction.
The sentence reads like an instruction-override prompt ("do not look at this line", "only look at ..."). On Vertex AI with Model Armor floor settings that enable prompt injection and jailbreak detection, requests whose only user-role content is this placeholder are blocked before the model runs. The other ADK languages use neutral wording: ADK Python and ADK TypeScript append "Handle the requests as specified in the System Instruction." when there are no contents, and "Continue processing previous requests as instructed. Exit or provide a summary if no more outputs are needed." when the last turn is not from the user; ADK Go uses the second sentence and appends nothing for empty contents.
Steps to Reproduce:
- Use
com.google.adk:google-adk1.10.1 (the code is unchanged in 1.11.0 and onmainatce882374) with a Vertex AI backedLlmAgentwhose task is fully described by its instruction, for example with inputs passed through session state and the runner called with a userContentwhose parts list is empty. - In the same Google Cloud project, enable Model Armor floor settings for Vertex AI with prompt injection and jailbreak detection in blocking mode (confidence threshold: high).
- Run the agent.
- The first model call is rejected by Model Armor. At unit level,
GeminiUtil.ensureModelResponse(ImmutableList.of())returns one user content with the placeholder text above.
Expected Behavior:
The placeholder turn added by ADK should not look like a prompt injection attempt, and should match the wording used by the other ADK languages.
Observed Behavior:
The Model Armor sanitize log entry of a blocked request (payload removed) reports:
"piAndJailbreakFilterResult": {
"confidenceLevel": "HIGH",
"matchState": "MATCH_FOUND",
"executionState": "EXECUTION_SUCCESS"
}
The other filters in the same entry returned NO_MATCH_FOUND. The inspected text was the system instruction followed by the placeholder line, and the placeholder was the only user-role content in every blocked request. The same requests succeeded before the detection was enabled, and ordinary chat requests in the same project, which end with user-typed text, were not blocked.
Model Armor returns one verdict per request, so the two sentences were also checked on their own. In the same project and settings, each sentence was typed as a plain user message in a new session of a chat agent (same system instruction for both): "Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction." was blocked by Model Armor, while "Handle the requests as specified in the System Instruction." (the ADK Python sentence for empty contents) was not. Only the sentence differed between the two requests, so the block comes from the wording of the Java sentence.
Environment Details:
- ADK Library Version (see maven dependency): 1.10.1, code unchanged in 1.11.0 and on
main(ce882374) - OS: Linux server (JDK 17); reproduced at unit level on Windows 11 / Microsoft Build of OpenJDK 17.0.19 / Maven 4.0.0-rc-3 (wrapper)
Model Information:
- Which model is being used: gemini-3.8-flash (Vertex AI)
🟡 Optional Information
Regression:
No — the wording has been the same since v0.1.0 (first in Gemini, later moved to GeminiUtil).
How often has this issue occurred?:
- Always (100%) for requests that contain no user-authored content.
Proposed fix:
Use the same wording as ADK Python and ADK TypeScript (a small PR will follow). Note that the Python empty-contents sentence was itself reported to trip Azure OpenAI's jailbreak filter in a LiteLLM code path (google/adk-python#4249; the wording was kept and the extra injection was removed in google/adk-python@d0102ec instead); Model Armor did not block it in the check above. Aligning the languages is proposed as the smallest change; making the placeholder text configurable would be an alternative if maintainers prefer.
- 主要语言
- Java
- 星标
- 1.7k
- 派生
- 433
- 平均合并
- 3 天 13 小时
- 30 天内合并 PR
- 42
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
google/adk-java 的其他 Issue
-
[spring-ai] ToolConverter silently drops enum and items from tool parameter schemas可能已有人在做 @hirematha 于 5 天前认领。 未关闭needs review
难度 2/5 1-3 小时 新手友好度 76/100
google/adk-java#1609 · 2 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
[spring-ai] Streaming responses ending with CJK punctuation (。!?) are misclassified as partial and never persisted to the session可能已有人在做 @hirematha 于 5 天前认领。 未关闭needs review
难度 2/5 1-3 小时 新手友好度 84/100
google/adk-java#1608 · 3 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
FirestoreSessionService compares event timestamps as text, reordering or skipping same-second events未关闭
难度 3/5 1-2 天 新手友好度 50/100
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 45/100
维护者通常 1 天内回复
-
FirestoreSessionService loses event fields on reload, breaking later turns and tool confirmations可能已有人在做 @innoprej 于 1 天前认领。 未关闭
难度 4/5 3-5 天 新手友好度 22/100
维护者通常 1 天内回复
相似的 Issue
-
Clock.MakeDate continues execution and returns a rolled-over instant after dispatching error on invalid date可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 1/5 1 小时以内 新手友好度 82/100
mit-cml/appinventor-sources#4155 ·
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 62/100
Hira-shi/PW1-DAI-Carrel-Egal-Eyer#28 ·
维护者通常 1 天内回复
-
`GET /v1/event/token/{uuid}` can report a BOM upload as done before policy evaluation and metrics have finished可能已有人在做 @Zargath 今天认领。 未关闭defect in triage
难度 2/5 1-3 小时 新手友好度 72/100
DependencyTrack/dependency-track#7646 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
objectionary/eo-graphs#80 ·