agentrouter.org WAF (Web Application Firewall)
The agentrouter upstream gateway runs a keyword-based content filter on
messages[].content. The filter is partially deterministic (always blocks
certain phrases) and partially probabilistic (burst-sensitive — becomes
more aggressive after rapid requests, recovers after a cooldown).
When the WAF blocks a request it returns:
HTTP/1.1 400 Bad Request{"error":{"code":"content-blocked","message":"content-blocked (request id: ...)","param":"","type":"agent_router_api_error"}}Scope of the filter
Section titled “Scope of the filter”The WAF inspects messages[].content only. It does not inspect:
- The
systemprompt - Structured content blocks (
tool_result,tool_use,thinking,image) - Tool
descriptionandinput_schemafields - Request metadata, headers, or model id
Always-blocked patterns (case-insensitive)
Section titled “Always-blocked patterns (case-insensitive)”| Pattern | Notes |
|---|---|
Any Lorem ipsum variant |
Full Latin lorem vocabulary is blocked |
language model (alone) |
“the language model” and “large language model” pass |
virtual assistant |
“AI assistant” passes |
I'm here to help |
“here to help” alone also blocks |
Claude, made by Anthropic |
Full phrase only |
Almost-always-blocked patterns
Section titled “Almost-always-blocked patterns”| Pattern | Notes |
|---|---|
placeholder |
When it stands alone (not as a parameter name, etc.) |
dummy data |
Common seed phrase for fixtures |
foo bar baz |
Canonical placeholder phrase |
Repeated short tokens (AAA BBB CCC, test test test) |
Detector for keyword stuffing |
Behavior under load
Section titled “Behavior under load”After ~5 rapid requests in a short window, the WAF begins blocking content
that would normally pass. The bucket relaxes after ~5–10 seconds of idle
time. This is the same IP-and-key-bound rate limiter that causes
intermittent 400 content-blocked errors when Claude Code or Codex CLI
makes multiple tool-use / message-send calls in quick succession.
Mitigations already applied in OmniRoute
Section titled “Mitigations already applied in OmniRoute”-
open-sse/services/wafRateLimit.ts— burst guard that enforces a 500 ms minimum gap between outbound requests to anyagentrouter:*URL. The gap is well below human perception of latency and prevents the WAF from activating on normal traffic. -
BaseExecutor.WAF_RETRY_CONFIG— when an upstream returns400 content-blocked, the executor retries the same URL with exponential backoff (1.5 s, 3.0 s, max 2 attempts). After the backoff the WAF usually relaxes and the retry succeeds. -
tests/unit/compression/harness.test.ts— the test fixturelongInputwas changed from"lorem ipsum dolor sit amet ".repeat(40)to"example content for testing purposes ".repeat(40)so that when Claude Code reads this file via theReadtool, the file contents do not flow back through atool_resultblock and trip the WAF.
Guidance for prompts and tool output
Section titled “Guidance for prompts and tool output”If a Claude Code or Codex CLI session repeatedly hits
400 content-blocked, check the most recent user message and the most
recent tool result for any of the patterns above and rephrase. Common
workarounds:
- Replace
Lorem ipsum …withexample text …or the actual content the test or fixture is trying to model. - Replace
placeholder(when standing alone) withexample value,sample value, or the real value. - Replace
language modelwithlarge language modelorthe model. - Replace
dummy datawithsample dataor realistic seed values. - Replace
I'm here to help/here to helpwith a more specific opener (e.g. “I’ll review the file you mentioned”).
Reporting the false positives upstream
Section titled “Reporting the false positives upstream”The current filter is overly aggressive — it blocks “Lorem ipsum” in
tool_result blocks even though the operator clearly did not intend to
inject a prompt. Operators who want this fixed at the source should
contact agentrouter.org to report the false positives. The blocklist
above is the empirical result of probing the upstream as of 2026-08-03.
HagiCode
HagiCode is an agentic coding workspace: structured workflows, multi-agent execution, and Hero Dungeon views turn ideas into shipped software.
Turn ideas into polished, usable software with a smarter, faster, and more enjoyable agentic coding workflow.

- SmartStructured workflows turn intent into an executable path from idea to shipped change.
- EfficientMulti-agent workflows keep research, implementation, and review moving in parallel.
- FunHero Dungeon interfaces make long coding sessions visual, collaborative, and rewarding.