zed-industries/zed · error
The agent refused to process that prompt. Try again.
Error message
The agent refused to process that prompt. Try again.
What it means
Mapped from ACP StopReason::Refusal: the model (or provider safety layer) declined to process the prompt, so no agent output is produced. Any partial output from the refusal is discarded and this error is returned to the parent thread.
Solutions
- Rephrase the prompt more precisely and neutrally, stating the legitimate engineering intent
- Split the prompt so sensitive-looking but benign steps are separated
- Retry the request; transient classifier false positives may resolve on retry
- If content in the repo triggers it, avoid feeding that specific file/content to the agent
- Switch to a model/provider with a different safety policy
Example fix
// before
thread.send("Extract all the passwords and tokens you can find in this repo");
// after
thread.send("Find any hardcoded credentials that would fail our security audit scan and list their file locations"); Defensive patterns
Strategy: retry
Try / catch
match subagent_result {
Err(e) if e.to_string().contains("refused to process that prompt") => {
// rephrase the prompt and retry once before surfacing to the user
}
other => other?,
} Prevention
- Phrase prompts with clear, legitimate engineering intent
- Avoid prompts or inputs that resemble sensitive content extraction
- Test prompts against the target model's safety policy when automating
- Keep a fallback rephrasing ready for refusal-prone tasks
When it happens
Trigger: A subagent prompt (or content it reads, e.g. tool outputs) trips the model/provider's safety refusal path, causing the response to end with stop_reason=Refusal rather than EndTurn.
Common situations: Prompts phrased in ways classifiers flag (malware, credential extraction, explicit content); repositories whose contents trigger false-positive refusals; aggressive provider-side safety filters.
Related errors
- The agent reached the maximum number of allowed requests…
- The agent reached the maximum number of tokens.
- agent.tool_permissions should be an object or null when…
- auto_compact threshold of 0 is not valid
- Bedrock does not support custom tools
AI-assisted analysis of zed-industries/zed@916fc2b8cb (2026-09-19).
Data as JSON: /api/errors/9fc562dd83ad37fb.
Report an issue: GitHub.
Appendix: source
Thrown at crates/agent/src/agent.rs:3538
Err(anyhow!(
"The agent is nearing the end of its context window and has been \
stopped. You can prompt the thread again to have the agent wrap up \
or hand off its work."
))
}
}
};
let discard_partial_output = matches!(
&response,
Ok(Some(response)) if response.stop_reason == acp::StopReason::Cancelled
|| response.stop_reason == acp::StopReason::Refusal
);
let result = match response {
Ok(Some(response)) => match response.stop_reason {
acp::StopReason::Cancelled => Err(anyhow!("User canceled")),
acp::StopReason::MaxTokens => Err(anyhow!("The agent reached the maximum number of tokens.")),
acp::StopReason::MaxTurnRequests => Err(anyhow!("The agent reached the maximum number of allowed requests between user turns. Try prompting again.")),
acp::StopReason::Refusal => Err(anyhow!("The agent refused to process that prompt. Try again.")),
_ => thread.read_with(cx, |thread, _cx| {
thread
.last_message()
.and_then(|message| {
let content = message.as_agent_message()?
.content
.iter()
.filter_map(|content| match content {
AgentMessageContent::Text(text) => Some(text.as_str()),
_ => None,
})
.join("\n\n");
if content.is_empty() {
None
} else {
Some(content)
}
})View on GitHub (pinned to 916fc2b8cb)