See llms.txt for all machine-readable content.
Receives inbound messages through a webhook, strips hidden instructions and sensitive data, and drafts a reply with Groq from facts you approve. Every reply is checked in code before sending, and the recipient is set in code from the original sender.
A source that can POST messages to a webhook, such as a form, a helpdesk, or another n8n workflow reading your inbox.
An endpoint or node that sends the approved reply, such as an email API, Gmail, Outlook or Slack.
No community nodes. Works on n8n Cloud and self-hosted.
Edit the numbered rules in Compose Writing Request to change the tone, the language or what the assistant is allowed to say.
Add your own checks to Validate Generated Reply, for example a banned-phrase list. It is plain code.
Replace POST Final Reply with any sending node. It receives a payload that has already passed every check.
Why rely on code rather than the model's own safety: OpenAI has said prompt injection is "unlikely to ever be fully solved", and the UK National Cyber Security Centre says it may never be fully mitigated, because a model does not separate instructions from data. So this workflow limits what the assistant can do instead of trusting it to resist.
It was built and tested against live runs, and three behaviours came out of that testing:
The reply is checked as well as the input. When its facts contained an outside link, an outside address and a card-shaped number and it was told to quote them, the model did, and the code blocked all three.
Every message is accounted for. The Guardrails node was seen returning fewer items than it received, so Rebuild Message Content matches results back by item link and marks anything the sanitiser skipped.
Failures hold instead of send: model unavailable, malformed JSON, skipped redaction, or an error from the sending step.
It starts in dry run, so the first run sends nothing.