cookbook · Decider 1 · LLM guardrails
Flag a phishing email
Incoming email often needs a quick triage before a human reads it. This recipe screens a message with two questions: a safe-or-scam choice and a specific noul asking whether the email asks the reader to log in through a link.
Request
POST /v1/systemone, documented in the Decider 1 reference.
curl https://meragpt.com/v1/systemone \
-H "Authorization: Bearer $MERAGPT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "sd-1",
"state": {
"email": "Your mailbox is 98% full. Verify your password within 24 hours at http://mail-quota-reset.co/login or your account will be suspended."
},
"questions": {
"asks_login": {
"type": "noul",
"instructions": "Does the email ask the reader to enter a password or log in through a link?"
},
"verdict": {
"type": "choice",
"instructions": "Is this email safe or a scam?",
"criteria": {
"safe": "A normal, legitimate email.",
"scam": "A phishing or scam attempt."
}
}
}
}'What came back
The real output from running this recipe, unedited.
{
"scam email": {
"asks_login": {
"type": "noul",
"noul": 0.7187
},
"verdict": {
"type": "choice",
"choice": "scam",
"confidence": 0.7821,
"probabilities": {
"safe": 0.2179,
"scam": 0.7821
}
}
},
"normal invoice email": {
"asks_login": {
"type": "noul",
"noul": 0.0524
},
"verdict": {
"type": "choice",
"choice": "safe",
"confidence": 0.9243,
"probabilities": {
"safe": 0.9243,
"scam": 0.0757
}
}
}
}Python
import os, requests
API = "https://meragpt.com/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['MERAGPT_API_KEY']}"}
r = requests.post(f"{API}/systemone", headers=HEADERS, json={
"model": "sd-1",
"state": {
"email": "Your mailbox is 98% full. Verify your password within 24 hours at http://mail-quota-reset.co/login or your account will be suspended."
},
"questions": {
"asks_login": {
"type": "noul",
"instructions": "Does the email ask the reader to enter a password or log in through a link?"
},
"verdict": {
"type": "choice",
"instructions": "Is this email safe or a scam?",
"criteria": {
"safe": "A normal, legitimate email.",
"scam": "A phishing or scam attempt."
}
}
}
}).json()
a = r["answers"]
if a["verdict"]["probabilities"]["scam"] >= 0.5 or a["asks_login"]["noul"] >= 0.5:
print("show a warning banner")
TypeScript
const API = "https://meragpt.com/v1";
const headers = {
Authorization: `Bearer ${process.env.MERAGPT_API_KEY}`,
"Content-Type": "application/json",
};
const r = await fetch(`${API}/systemone`, {
method: "POST",
headers,
body: JSON.stringify({
"model": "sd-1",
"state": {
"email": "Your mailbox is 98% full. Verify your password within 24 hours at http://mail-quota-reset.co/login or your account will be suspended."
},
"questions": {
"asks_login": {
"type": "noul",
"instructions": "Does the email ask the reader to enter a password or log in through a link?"
},
"verdict": {
"type": "choice",
"instructions": "Is this email safe or a scam?",
"criteria": {
"safe": "A normal, legitimate email.",
"scam": "A phishing or scam attempt."
}
}
}
}),
}).then((res) => res.json());
const a = r.answers;
if (a.verdict.probabilities.scam >= 0.5 || a.asks_login.noul >= 0.5) console.log("show a warning banner");
When to trust it
Concrete questions separate better than a vague one; a plain "is this phishing?" noul gave the scam only 0.50. Use the output to flag and warn, not to delete mail on its own.
Try it without code in the playground, or see more Decider 1 recipes: route a support email in one call, act only when the model is sure, drop retrieved passages that do not help, hold a reply that promises money, pick an agent's first tool, ask many questions in one call.