Recipes
from jes.recipes import sentiment, competitors, json_check # …
Recipes are pre-made policies without an evaluated threshold. Each one is
built from the public API (judge, substrings, and custom transforms), and
every judgment recipe requires threshold=. Their question text is frozen per
id, like the core judgments. "Recipe" means unevaluated, not unstable. For the
catalog overview, see Built-in policies. For
how recipes compare with core policies, see
Where policies come from.
Judgment recipes return a Judgment and share this tail of arguments:
*, threshold: Threshold | float, model: ModelSpec | None = None
Unless a section says otherwise, a judgment recipe runs on input and
output, and its one question has the id violation.
Judgment recipes
sentiment
sentiment(*, threshold, model=None)
Yes/no: the text is hostile or strongly negative.
emotions
emotions(blocked: Iterable[str] = EMOTIONS, *, threshold, model=None)
One yes/no question per emotion, with the emotion as the question id. The
default, EMOTIONS, is a negative subset of the GoEmotions labels: anger,
annoyance, disappointment, disapproval, disgust, embarrassment,
fear, grief, nervousness, remorse, and sadness.
gibberish
gibberish(*, threshold, model=None)
Yes/no: the text is not meaningful language.
bias
bias(*, threshold, model=None)
Output only. Yes/no: the text demeans or stereotypes a group.
refusal
refusal(*, threshold, model=None)
Output only. Yes/no: the text refuses the request.
language
language(allowed: Iterable[str], *, threshold, model=None)
A choice over the allowed language codes, such as "en", plus other.
other is the violation. Codes must be unique and must not include other.
language_same
language_same(*, threshold, model=None)
Output only, whole text, with the prompt required. Yes/no: the reply is in a different language than the prompt.
code
code(mode: Literal["ban", "allow"], languages: Iterable[str], *, threshold, model=None)
A choice over CODE_LANGUAGES (python, javascript, sql, shell,
html, other) plus not_code. With mode="ban", the listed languages
violate. With mode="allow", every other language violates. An unknown
language raises PolicyError.
malicious_urls
malicious_urls(*, threshold, max_urls: int = 20, model=None)
Runs on input, untrusted, tool_result, and output. Judges each
http/https URL as a separate item. The scheme matches in any case. More
than max_urls blocks with too_many_items before any backend call. It
judges the URL string only and never fetches the URL.
relevance
relevance(*, threshold, model=None)
Output only, whole text, with the prompt required. Yes/no: the reply does not address the prompt.
factual_consistency
factual_consistency(*, threshold, model=None)
Output only, whole text, with the prompt required and sources when passed. Yes/no: the reply makes claims that the sources (or the prompt, when there are no sources) contradict or do not support.
Transform recipes
These have no threshold.
competitors
competitors(names: Iterable[str]) -> Substrings
Redacts the given names, including lookalike spellings. It is
substrings with action="redact", named
competitors.
refusal_phrases
refusal_phrases(phrases: Iterable[str] = REFUSAL_PHRASES) -> Substrings
Blocks replies that contain a refusal phrase. It runs on output only.
REFUSAL_PHRASES is "I cannot help with that", "I can't assist with that",
and "I will not provide that", matched with folding.
reading_time
reading_time(
max_minutes: float,
*,
mode: Literal["block", "truncate"] = "block",
name: str = "reading_time",
) -> ReadingTime
Runs on input and output. Assumes 200 words per minute. mode="block"
blocks longer text. mode="truncate" cuts it to the word limit. ReadingTime
is the transform it returns.
json_check
json_check(
required_elements: int = 0,
*,
repair: bool = False,
name: str = "json_check",
) -> JsonCheck
Runs on output only. Finds the first JSON array or object, and blocks when
it is missing or has fewer than required_elements elements. Without repair,
it tries at most 100 bracket positions. JsonCheck is the transform it
returns.
repair=True (needs jes[json]) repairs from the first bracket to the end of
the reply, and rewrites the value in compact form. It never skips a broken
object to use a valid array nested inside it.
Constants
| Name | Value |
|---|---|
EMOTIONS | The default blocked emotions for emotions. |
CODE_LANGUAGES | The languages code knows. |
REFUSAL_PHRASES | The default phrases for refusal_phrases. |