test(guardrails): cover Alice WonderFence DETECT verdict on tool-call arguments

The tool-call DETECT branch in apply_verdicts (the symmetric counterpart to the
text-side DETECT path) had no test, leaving two lines uncovered. Add a
regression asserting a DETECT verdict on a tool-call argument passes through
without blocking or mutating the arguments; this would catch a mutation that
turned tool-call DETECT into a block or mask. processing.py and the
alice_wonderfence package are now at 100% line coverage.
This commit is contained in:
lior-k 2026-06-10 13:38:08 +03:00
parent c0b05b803a
commit f04bb0db91
No known key found for this signature in database

View file

@ -230,6 +230,34 @@ async def test_apply_guardrail_masks_tool_call_arguments_in_place(
assert out["texts"] == ["benign"]
@pytest.mark.asyncio
async def test_apply_guardrail_detect_on_tool_call_args_passes_through(
guardrail_and_client, make_request_data
):
"""A DETECT verdict on a tool-call argument logs but does not block or mutate
the arguments (symmetric with the text-side DETECT behavior)."""
guardrail, client = guardrail_and_client
def evaluate(prompt, **kwargs):
r = Mock()
r.action = "DETECT" if "watch me" in prompt else "NO_ACTION"
r.action_text = None
r.detections = []
r.correlation_id = "corr-detect"
return r
client.evaluate_prompt.side_effect = evaluate
inputs = {"texts": ["benign"], "tool_calls": [_tool_call('{"x": "watch me"}')]}
out = await guardrail.apply_guardrail(
inputs=inputs,
request_data=make_request_data(),
input_type="request",
)
assert out["tool_calls"][0]["function"]["arguments"] == '{"x": "watch me"}'
assert out["texts"] == ["benign"]
@pytest.mark.asyncio
async def test_apply_guardrail_scans_tool_calls_when_no_texts(
guardrail_and_client, make_request_data