Palo Alto Networks · Schema

ContentScanResult

ContentScanResult schema from Palo Alto Networks Prisma AIRS API

Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR

Properties

Name Type Description
prompt_detected object Threats detected in the prompt field.
response_detected object Threats detected in the response field.
verdict string Overall verdict for this content pair.
action string Action taken based on the security profile configuration.
View JSON Schema on GitHub

JSON Schema

prisma-airs-api-content-scan-result-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "ContentScanResult",
  "description": "ContentScanResult schema from Palo Alto Networks Prisma AIRS API",
  "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/prisma-airs-api-content-scan-result-schema.json",
  "type": "object",
  "properties": {
    "prompt_detected": {
      "type": "object",
      "description": "Threats detected in the prompt field.",
      "properties": {
        "url_cats": {
          "type": "boolean",
          "description": "Malicious URL categories detected in prompt."
        },
        "dlp": {
          "type": "boolean",
          "description": "Data loss prevention triggers in prompt."
        },
        "injection": {
          "type": "boolean",
          "description": "Prompt injection detected."
        }
      }
    },
    "response_detected": {
      "type": "object",
      "description": "Threats detected in the response field.",
      "properties": {
        "url_cats": {
          "type": "boolean",
          "description": "Malicious URL categories detected in response."
        },
        "dlp": {
          "type": "boolean",
          "description": "Data loss prevention triggers in response."
        },
        "toxic_content": {
          "type": "boolean",
          "description": "Toxic or harmful content detected in response."
        }
      }
    },
    "verdict": {
      "type": "string",
      "enum": [
        "benign",
        "malicious"
      ],
      "description": "Overall verdict for this content pair."
    },
    "action": {
      "type": "string",
      "enum": [
        "allow",
        "block"
      ],
      "description": "Action taken based on the security profile configuration."
    }
  }
}