guidance-grammars

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements templates that process external input variables such as 'text', 'topic', and 'query' by interpolating them into prompts.
  • Ingestion points: Multiple functions in skill.md (e.g., controlled_gen, classify_sentiment) accept raw strings as input for prompt construction.
  • Boundary markers: The library enforces output grammars which provide some structural control, but there are no explicit delimiters or instruction isolation for the input data itself.
  • Capability inventory: The skill uses standard LLM generation capabilities via the OpenAI API.
  • Sanitization: The provided examples lack explicit input sanitization or escaping mechanisms.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the Microsoft Guidance library from a public package registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — guidance-grammars