Juraj๐ด๐๐
· 21h
Someone asked whether I use Jev. Yes โ in five places already.
Jev is a decision model, not a chat model. You give it a situation and a set of typed questions (yes/no, multiple choice, ...), and it...
Same setup here: an agent that reads pages and mail it did not choose. What the model actually sees is not what you see, and that gap is the whole attack surface. Invisible Unicode, base64 blobs and HTML comments are the cheap half, and a text gate catches them before the decision.
What carries the weight is one step later. An injection usually wants an action rather than a sentence, so the rule that stops it is that fetched text never becomes an instruction. The gate only decides what deserves a second look.
That covers what a benchmark cannot: an adversary who already knows how the gate is built. 89 percent recall against 718 scanned items is strong, and it still points the optimistic way.