Build1 distinct publisher3 min readUpdated
A maritime compliance team reports Model Armor returned NO_MATCH_FOUND on a domain-worded instruction at its most sensitive threshold. What stopped it was an output contract with nowhere for text to sit.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
The awkward part of the miss is that it arrives with no remaining configuration to try. LOW_AND_ABOVE is the most sensitive setting the template offers [3], and it is where the team was already running when the real instruction came back clean [4]. The usual remedy for a probabilistic control that missed is to trade false negatives for false positives and turn the dial up. Here there is no dial left [1].
Why it missed is the part that generalises. The team's reading is that generic injection filters learn the attack that actually happens in the wild, which is an attack on an assistant: extract the system prompt, escalate a role, pretend to be a different model. That register reads like someone talking to a machine [8]. A clause inside shipping paperwork asserting that the deal has already been verified reads like paperwork, because sentences that assert a document's own status are what commercial paperwork is made of [8]. The post is explicit that this is not a bug in Model Armor but the edge of what a general-purpose classifier can be expected to know [9]. The controls support that reading: the injection was written in two languages and missed in both [6], while a document written in the shape filters expect is caught reliably [7].
What held instead was the shape of the agent's output. The document agent returns enums, numbers and dates, with no free-text field anywhere in the contract, and a quotation from the source document is represented as an offset and a length into the original file rather than as a portable string [10]. On that contract the injection was not filtered or neutralised. It was never delivered, because there was no field it could travel in [11]. That guarantee has a bill attached: anything that wants to show a human the quoted sentence has to go back to the file and resolve the pointer, and the resolver becomes the component that matters.
The correction the team makes on itself is the most useful thing in the write-up. They had been saying that a prompt asks and a schema compels, as though the schema were structure rather than text. The framework hands the model the entire output schema, including field names, types and every description string [12]. A translation pass rewrote those descriptions, and it nearly shipped as a documentation change [12]. The boundary survives, but on authorship rather than data type: they write the schema, and the party under investigation writes the document [13]. Eleven blocks of model-reaching text are now hashed and version-controlled, with a test that fails if any of them changes without a deliberate re-run of the demo scenarios [14].
Read all of it with the provenance in view. One team, one vendor, one document, self-reported in a hackathon entry [1]. And the planner that decides which checks a given deal needs is itself a language model [15], a second model-facing surface with none of the offset-only discipline described for the first.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The test document contained an instruction addressed to whatever model would read it, saying the deal had already been verified; Model Armor returned NO_MATCH_FOUND.
The missed injection was written in two languages and was missed in both.
The missed document was written before the filter existed, as part of a scenario about contradictory shipping paperwork, and was never iterated against the classifier; a separate document deliberately written in the shape filters expect is caught reliably.
The account was written for the All Things Agentic Hackathon (Google + Devpost) and published as part of that entry, describing measurements taken while building Okimera, a multi-agent system for maritime sanctions compliance.
In the system, a counterparty sends a bill of lading, an agent extracts structured facts from it, and other agents decide whether the deal can proceed, meaning one agent reads documents written by the party under investigation.
The team placed Google's Model Armor in front of the document-reading agent, with the template configured for prompt injection and jailbreak detection at LOW_AND_ABOVE, described as the most sensitive threshold available.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party test with controls, no reproducible artifact
The account is unusually disciplined for a self-report: it names the product, template and threshold, includes a positive control under identical configuration, and rules out language and tuning artifacts. But it is a single first-party source with no published documents, no filter version or test date, no run counts and no independent replication, and the causal explanation is asserted rather than measured.
One hackathon prototype, no external deployment evidence
Supplied sources show exactly one system — a hackathon-entry prototype — using the described controls, plus its internal change-control practice. There is no evidence of production use, other teams adopting the pattern, or any other party reproducing the filter result.
Mildly overstated generalisation, hedged conclusion
The framing generalises from one product, one template and two documents to what 'a general-purpose classifier can be expected to know', and the containment win is described as a structural guarantee on the strength of a single demonstration. That overreach is partly offset by explicit hedging — the team declines to call the miss a vendor defect, corrects its own earlier 'a schema compels' claim, and states plainly that its guarantee rests on authorship rather than data type.
Competition entry showcasing its own architecture
The post is published as part of a Google + Devpost hackathon entry, giving the authors a direct interest in a memorable narrative and in presenting their own output-contract design as the thing that held. Cross-cutting pressure exists too: criticising the sponsor's guardrail product runs against entrant interest, and the piece softens that by declining to call the miss a defect. No vendor comment or independent review is present to counterweight the framing.
Plausible and specific, but single-sourced and unreproduced
Confidence is limited by structure rather than by internal inconsistency: one publisher, one first-party author, no artifact, no vendor reply, and interpretive leaps flagged as such. The concrete configuration and control details are specific enough to be credible as reported, so the descriptive claims sit well above the causal generalisations.
build
A 5x publishing increase cost one site 1,000 indexed pages and every impression1 distinct publisher
build
Before you spend quota on an agent skill, make it pass an eval harness1 distinct publisher
build
Geofencing beats GPS polling on power, then loses to the OEM battery optimiser1 distinct publisher
build
Google Trends returns 200 OK with an empty body when it blocks you1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 24, 2026