prompt-governance
>
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Prompt Governance
> Category: Engineering
> Domain: AI Governance
Overview
The Prompt Governance skill provides tools for auditing prompts for security vulnerabilities, bias, and safety issues, plus managing a versioned catalog of approved prompts. Essential for organizations deploying LLM-based applications at scale.
Clarify First
Before auditing or cataloging, confirm these inputs. If any is unknown or vague, ASK — do not assume:
- [ ] Target prompt(s) — the exact file/text to audit or the catalog dir to manage (the subject of every check)
- [ ] Task: audit vs catalog management — selects
prompt_auditor.pyvsprompt_catalog_manager.pyand the whole workflow - [ ] Check focus — injection / bias / safety (sets which auditor checks run and the pass/fail bar)
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Quick Start
# Audit a prompt for security and safety issues
python scripts/prompt_auditor.py --file system_prompt.txt
# Audit with specific focus
python scripts/prompt_auditor.py --text "You are a helpful assistant..." --checks injection,bias,safety
# Initialize a prompt catalog
python scripts/prompt_catalog_manager.py --init --catalog-dir ./prompts
# Add a prompt to the catalog
python scripts/prompt_catalog_manager.py --add --name "customer-support-v1" --file prompt.txt --catalog-dir ./prompts
# List all prompts in catalog
python scripts/prompt_catalog_manager.py --list --catalog-dir ./prompts
Tools Overview
| Tool | Purpose | Key Flags |
|------|---------|-----------|
| prompt_auditor.py | Audit prompts for injection, bias, and safety | --file, --text, --checks, --format |
| prompt_catalog_manager.py | Manage versioned prompt catalog | --init, --add, --list, --diff, --catalog-dir |
Workflows
Prompt Review Process
- Author writes or modifies a prompt
- Run
prompt_auditor.pyfor automated checks - Review findings and address critical issues
- Add approved prompt to catalog with
prompt_catalog_manager.py - Deploy from catalog (never from ad-hoc sources)
Prompt Versioning
- Store all prompts in catalog with semantic versioning
- Use
--diffto compare versions before promotion - Maintain audit trail of all prompt changes
- Roll back to previous versions when issues detected
Reference Documentation
- [Prompt Governance Framework](references/prompt-governance-framework.md) - Policies, review processes, and compliance requirements
Common Patterns
Prompt Lifecycle
Draft -> Audit -> Review -> Approve -> Deploy -> Monitor -> Retire
Governance Checklist
- No injection vulnerabilities
- No harmful content generation potential
- Appropriate bias mitigation
- Clear scope boundaries
- Output format constraints
- Error handling instructions
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。