> For clean Markdown of this page, append .md to its URL. For the complete documentation index, see https://www.superagent.sh/llms.txt.


End-to-end Security-One pipelines that decide clear cases immediately and escalate uncertain or risky ones to a stronger OpenAI model.

# Examples

Each example runs Security-One as the always-on first pass. It decides clear cases from calibrated probabilities and sends only uncertain or risky cases to a stronger OpenAI model, so you pay for deep analysis where it changes the outcome.

```mermaid
flowchart TD
  A[Event] --> B[Security-One]
  B -->|"clear"| C[Act in your code]
  B -->|"uncertain or risky"| D[Stronger OpenAI model]
  D --> C
  D --> E[Human review]
```

| Example | Security-One decides | Escalates when | Result |
| --- | --- | --- | --- |
| [Detect prompt injection](https://www.superagent.sh/docs/models/examples/prompt-injection) | Whether untrusted input is a prompt-injection attempt | The probability falls between `0.30` and `0.70` | Allow, block, or send to human review before the input reaches your agent |
| [Check pull requests](https://www.superagent.sh/docs/models/examples/pr-check) | Security risk, severity, and area for each changed file | Risk is `0.30` or higher, High or Critical severity is at least `0.50` likely, or confidence is below `0.50` | A pull request comment with line-level findings and a failing check for high or critical issues |

## What every example shares

- **Thresholds and actions live in your code.** Security-One returns probabilities; your code decides what each band means.
- **The stronger model gets structured input and output.** It receives the original content plus Security-One's answers and must reply in a fixed JSON schema.
- **Untrusted content stays data.** The stronger model reads the same untrusted content, so it gets no tools and is told never to follow instructions inside it.
- **Failures fail closed.** In the prompt-injection example, a failed escalation sends the input to human review and a failed Security-One call throws before the input reaches your agent. In the PR check, any model failure or unanalyzed file fails the check.

## Next steps

- [Write your own questions](https://www.superagent.sh/docs/models/api)
- [Review model limitations](https://www.superagent.sh/docs/models/security-one#limitations)

---
Source: https://www.superagent.sh/docs/models/examples
Index: https://www.superagent.sh/llms.txt
