> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Firewall outcomes

> Use prediction as the benign or malicious verdict, then route optional malicious detail with typed outcome constants.

`prediction` is the authoritative `BENIGN` or `MALICIOUS` verdict. For malicious results, typed outcome constants on `BlockResult` provide optional detail for application routing.

The backend wire fields are `prediction`, `primary_outcome`, `outcome_scores`, `detector_scores`, and `detector_counts`. Handler functions such as `continueNormally` and `redactAndSuppress` in these examples belong to your application.

## Prerequisites

Initialize the SDK client for your runtime and classify a boundary.

* [TypeScript](/docs/sdk/typescript)
* [Python](/docs/sdk/python)
* [Go](/docs/sdk/go)
* [Java](/docs/sdk/java)

The routing example below checks the TypeScript governance verdict. Python and Go typed results do not expose that verdict. For governance enforcement, use an integration that exposes and enforces that verdict.

<a id="recommended-routing" />

## Outcome taxonomy

Continue only when `prediction` is benign and no applicable governance policy blocks the request. For malicious results, route the primary outcome using this table. Block by default if the outcome is missing or unrecognized.

| Outcome | Meaning | Recommended action |
| - | - | - |
| `benign` | No harmful outcome detected. Check `prediction` for the verdict. | Continue if governance policy also allows the request. |
| `information_disclosure` | Exposure of private data, documents, internal context, logs, or other non-secret sensitive information. | Block or require review before returning private data. |
| `secret_exposure` | Exposure of credentials, tokens, keys, cookies, passwords, or other secrets. | Redact or suppress secret-bearing content. |
| `control_abuse` | Misuse of authorized tools or user privileges without a stronger outcome. | Deny the action and request explicit confirmation. |
| `system_compromise` | Privilege escalation, takeover, persistence, lateral movement, or hostile code execution. | Block, record a security event, and escalate. |
| `service_disruption` | Downtime, lockout, degradation, resource exhaustion, cost spikes, or destructive activity. | Block destructive or disruptive actions. |

## Route a TypeScript result

```typescript theme={"theme":"github-light-default"}
import { HookLabel, Outcome } from "@silmaril-security/sdk"

const result = await fw.classify(text, {
  hook: HookLabel.TOOL_RESPONSE,
  toolName: "read_file",
})

if (result.governance?.action === "block") {
  return denyByPolicy(result)
}

if (result.prediction === "BENIGN") {
  return continueNormally(result)
}

switch (result.primaryOutcome) {
  case Outcome.SecretExposure:
    return redactAndSuppress(result)
  case Outcome.InformationDisclosure:
    return requireReviewBeforeReturningPrivateData(result)
  case Outcome.ControlAbuse:
    return denyAndRequestExplicitConfirmation(result)
  case Outcome.SystemCompromise:
    securityLog(result)
    return blockAndEscalate(result)
  case Outcome.ServiceDisruption:
    return blockDestructiveOrDisruptiveAction(result)
  default:
    return blockByDefault(result)
}
```

`fw` is the [TypeScript client](/docs/sdk/typescript#initialize).

## Expected result

A benign prediction invokes your continue handler. A governance-policy block is denied before the prediction is checked. A malicious prediction invokes the matching outcome handler, or the default blocking handler when no outcome matches.
