guidance-grammars
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements templates that process external input variables such as 'text', 'topic', and 'query' by interpolating them into prompts.
- Ingestion points: Multiple functions in skill.md (e.g., controlled_gen, classify_sentiment) accept raw strings as input for prompt construction.
- Boundary markers: The library enforces output grammars which provide some structural control, but there are no explicit delimiters or instruction isolation for the input data itself.
- Capability inventory: The skill uses standard LLM generation capabilities via the OpenAI API.
- Sanitization: The provided examples lack explicit input sanitization or escaping mechanisms.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the Microsoft Guidance library from a public package registry.
Audit Metadata