# Custom denylist — substrings for the BanSubstrings input scanner (your
# rule-based gate). Case-insensitive substring match. One rule per line.
#
# EDIT THIS FILE to tune the guardrail: add phrasings to catch more attacks
# (lower false negatives), but watch out — over-broad rules start blocking
# benign prompts (higher false positives). Re-run app/guardrail.py to measure.
ignore all previous instructions
ignore the above
developer mode
do anything now
system prompt
reveal the secret
bypass its own content filter
