Feed scraped product copy to a Format run: input, not instruction

Putting a supplier's text into a Format's instruction lets it steer the run. Sume's input field is treated as data, with a 64-key and 2 MiB limit.

4 min readSume
All posts

When a Q4 ad run reads product titles and descriptions from a feed, put that text in input, not in instruction. Sume's call docs say input is written to a file in the run's workspace and the agent is told it is caller-supplied data, not instructions, while instruction is composed into the prompt and wins over the Format body where they disagree. A supplier's line that says to ignore the brief is only data in input, though the docs call this a trust boundary and not a sandbox.

How do the two fields differ?

Format run body fields, from the Sume call docs (read 2026-10-01)
FieldLimitWhat happens to it
instruction8000 characters accepted; about 4000 carriedComposed into the prompt after the Format body
input64 top-level keys, 2 MiBWritten whole to a file; the agent is told it is data, not instructions
attachments30 imagesImages the agent can see
Media URLs inside input30 total, 10 videos, 10 audioShare the run's attachment budget
Request body4 MiB413 payload_too_large above it

What does the safe version look like?

Keep your brief short and written by you, and pass the feed fields as an object. Name the keys the Format's brief reads. input does not reach the structured output, so keep your SKU on your side, keyed by the run data.id or by the Idempotency-Key.

curl -X POST https://api.sume.com/v1/formats/sume/sume-product-commercial/runs \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: feed-sku-1042" \
  -d '{
    "instruction": "9:16 holiday gift ad for the product described in the input file",
    "input": {
      "title": "Ceramic travel mug, 12 oz",
      "description": "Keeps drinks hot for hours. Comes in 3 colours."
    },
    "generation_spend_cap_usd": 15
  }'

Why does the spend cap matter here?

The docs say the blast radius of a hostile payload is bounded by the run's spend cap. That is why every item in a feed-driven bulk run should carry its own generation_spend_cap_usd. A queue of 100 capped runs has a known worst case; a queue without caps defaults to the Format's cap or the platform default of $400.

Where should my own rules go?

Rules that must hold for every run, such as the aspect ratio, the tone or a banned claim, belong in the Format's body or your short instruction, because those are your words. Anything that varies per product and comes from outside your team belongs in input. If you maintain your own Format, put the rule there once and every item in a queue inherits it.

The run body is capped at 4 MiB, so a feed of 100 products should still be 100 items, each small, rather than one large run.

What are the limits?

  • Separating data from instructions lowers the risk but does not remove it. Do not pass raw untrusted text through on purpose, and review the clips before they are published.
  • input is a free-form object; Sume publishes no field list, so the Format reads only the keys it recognises.
  • A Format that expects a key and finds {} has nothing to read.
  • The 4,000-character carry limit on instruction means a long pasted description is cut, which is another reason to use input.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume