Skip to main content

Recipes

from jes.recipes import sentiment, competitors, json_check # …

Recipes are pre-made policies without an evaluated threshold. Each one is built from the public API (judge, substrings, and custom transforms), and every judgment recipe requires threshold=. Their question text is frozen per id, like the core judgments. "Recipe" means unevaluated, not unstable. For the catalog overview, see Built-in policies. For how recipes compare with core policies, see Where policies come from.

Judgment recipes return a Judgment and share this tail of arguments:

*, threshold: Threshold | float, model: ModelSpec | None = None

Unless a section says otherwise, a judgment recipe runs on input and output, and its one question has the id violation.

Judgment recipes​

sentiment​

sentiment(*, threshold, model=None)

Yes/no: the text is hostile or strongly negative.

emotions​

emotions(blocked: Iterable[str] = EMOTIONS, *, threshold, model=None)

One yes/no question per emotion, with the emotion as the question id. The default, EMOTIONS, is a negative subset of the GoEmotions labels: anger, annoyance, disappointment, disapproval, disgust, embarrassment, fear, grief, nervousness, remorse, and sadness.

gibberish​

gibberish(*, threshold, model=None)

Yes/no: the text is not meaningful language.

bias​

bias(*, threshold, model=None)

Output only. Yes/no: the text demeans or stereotypes a group.

refusal​

refusal(*, threshold, model=None)

Output only. Yes/no: the text refuses the request.

language​

language(allowed: Iterable[str], *, threshold, model=None)

A choice over the allowed language codes, such as "en", plus other. other is the violation. Codes must be unique and must not include other.

language_same​

language_same(*, threshold, model=None)

Output only, whole text, with the prompt required. Yes/no: the reply is in a different language than the prompt.

code​

code(mode: Literal["ban", "allow"], languages: Iterable[str], *, threshold, model=None)

A choice over CODE_LANGUAGES (python, javascript, sql, shell, html, other) plus not_code. With mode="ban", the listed languages violate. With mode="allow", every other language violates. An unknown language raises PolicyError.

malicious_urls​

malicious_urls(*, threshold, max_urls: int = 20, model=None)

Runs on input, untrusted, tool_result, and output. Judges each http/https URL as a separate item. The scheme matches in any case. More than max_urls blocks with too_many_items before any backend call. It judges the URL string only and never fetches the URL.

relevance​

relevance(*, threshold, model=None)

Output only, whole text, with the prompt required. Yes/no: the reply does not address the prompt.

factual_consistency​

factual_consistency(*, threshold, model=None)

Output only, whole text, with the prompt required and sources when passed. Yes/no: the reply makes claims that the sources (or the prompt, when there are no sources) contradict or do not support.

Transform recipes​

These have no threshold.

competitors​

competitors(names: Iterable[str]) -> Substrings

Redacts the given names, including lookalike spellings. It is substrings with action="redact", named competitors.

refusal_phrases​

refusal_phrases(phrases: Iterable[str] = REFUSAL_PHRASES) -> Substrings

Blocks replies that contain a refusal phrase. It runs on output only. REFUSAL_PHRASES is "I cannot help with that", "I can't assist with that", and "I will not provide that", matched with folding.

reading_time​

reading_time(
max_minutes: float,
*,
mode: Literal["block", "truncate"] = "block",
name: str = "reading_time",
) -> ReadingTime

Runs on input and output. Assumes 200 words per minute. mode="block" blocks longer text. mode="truncate" cuts it to the word limit. ReadingTime is the transform it returns.

json_check​

json_check(
required_elements: int = 0,
*,
repair: bool = False,
name: str = "json_check",
) -> JsonCheck

Runs on output only. Finds the first JSON array or object, and blocks when it is missing or has fewer than required_elements elements. Without repair, it tries at most 100 bracket positions. JsonCheck is the transform it returns.

repair=True (needs jes[json]) repairs from the first bracket to the end of the reply, and rewrites the value in compact form. It never skips a broken object to use a valid array nested inside it.

Constants​

NameValue
EMOTIONSThe default blocked emotions for emotions.
CODE_LANGUAGESThe languages code knows.
REFUSAL_PHRASESThe default phrases for refusal_phrases.