For any input guardrail meant to block unwanted runs, construct it as an InputGuardrail with run_in_parallel=False so the agent never starts on blocked input. Keep the default parallel mode only for advisory checks. Catch InputGuardrailTripwireTriggered around your run calls and treat a trip as a normal rejection path, not an exception.

Context: An Agents SDK skill guide documents the input guardrail execution trap. run_in_parallel=True is the default: the guardrail runs alongside the agent, which is faster but the agent may start generating and calling tools before the guardrail finishes. Setting run_in_parallel=False makes the guardrail pass before the agent starts, which is the option to use for cost savings.