Key Prompt Template Rules in guardrails.md for the Patent Disclosure Skill

The guardrails.md files across the handsomestWei/patent-disclosure-skill repository enforce six mandatory safety categories—scope declaration, prohibited actions, configuration verification, output handling, dialogue constraints, and round limits—to ensure skills activate only after explicit user consent while strictly isolating data and preventing unauthorized cross-package execution.

The handsomestWei/patent-disclosure-skill repository employs a rigorous safety framework defined in multiple guardrails.md files that standardize how LLM prompt templates must behave under specific operational constraints. These prompt template rules in guardrails.md act as a template-level safety net, ensuring that skills for patent examination, policy briefs, and docket coordination remain dormant until explicitly invoked, while mandating configuration checks and data sanitization at every interaction boundary.

Scope and Explicit Activation Rules

According to the source code, each guardrails.md declares that safety constraints are optional yet binding, activating only after an explicit user request.

In skills/patent-oa/prompts/guardrails.md (lines 5–10), skills/patent-exam-policy/prompts/guardrails.md (lines 5–9), and skills/patent-docket/prompts/guardrails.md (lines 5–9), the documentation specifies that guardrails describe main use-cases—such as Q&A draft generation for Office Actions (OA), policy brief creation, and docket coordination—while remaining inactive until the user explicitly triggers the skill.

Prohibited Actions and Security Constraints

The guardrails explicitly hard-prohibit five critical categories of unsafe behavior across all skill packages.

As defined in skills/patent-oa/prompts/guardrails.md (lines 13–20), skills/patent-exam-policy/prompts/guardrails.md (lines 11–18), and skills/patent-docket/prompts/guardrails.md (lines 13–16), skills must never:

  • Ingest or emit unsanitized client data
  • Generate long answers without a retrieval hit
  • Modify other skill packages or invoke their tools/ modules
  • Embed or echo API keys or other secrets
  • Output official Word documents before user confirmation

This isolation ensures that the OA skill cannot interfere with the docket skill's internals, and no confidential patent data leaks through unsanitized outputs.

Configuration Requirements Before Retrieval

Before any vector-based retrieval operates, the skill must complete a strict configuration workflow.

The rules in skills/patent-oa/prompts/guardrails.md (lines 25–36) and skills/patent-exam-policy/prompts/guardrails.md (lines 25–30) mandate that the skill:

  1. Read the dedicated configuration prompt (configure_embedding.md)
  2. Execute the configuration script (config.py)
  3. Run self-tests to verify the embedding setup
  4. Rebuild the configuration only after human confirmation if tests fail

This ensures that retrieval-augmented generation (RAG) components never execute against unverified or misconfigured vector stores.

Output Rules and File Locations

Generated artifacts must follow strict filesystem conventions and visibility constraints.

According to skills/patent-oa/prompts/guardrails.md (lines 41–49) and skills/patent-docket/prompts/guardrails.md (lines 19–26), all outputs must be saved under package-specific directories such as outputs/oa/ or outputs/docket/. Furthermore:

  • Human-readable summaries must remain concise
  • Drafts are strictly internal working documents
  • Final Microsoft Word files are generated only after explicit user acceptance

Dialogue Interaction Guidelines

The guardrails enforce conversational economy to prevent prompt injection and context overflow.

As specified in skills/patent-oa/prompts/guardrails.md (lines 49–50) and skills/patent-docket/prompts/guardrails.md (lines 27–30), skills must:

  • Keep messages short and phase-aware
  • Inform the user of the current round or processing phase
  • Avoid re-presenting long prompts or system instructions from other packages

Round Limits for Docket Coordination

The docket skill imposes a strict lifecycle constraint on case handling, enforced by skills/patent-docket/tools/validate_docket.py.

In skills/patent-docket/prompts/guardrails.md (lines 11–18), the rules specify that any single case may proceed through at most three rounds of interaction. Phase transitions must strictly follow the definitions in phases.yaml, preventing infinite loops or unbounded conversation streams in patent docket management.

Implementation Examples

The following Python patterns demonstrate compliance with the prompt template rules in guardrails.md:

Configuration Enforcement


# Example: Enforcing configuration before using embeddings (OA skill)

from tools.config import recommend, set, selftest

# 1️⃣ Must read the configure_embedding prompt first (guardrail)

# 2️⃣ Run recommendation script

recommend()

# 3️⃣ Ask user for embedding preset or custom parameters

preset = ask_user("Choose embedding preset or provide custom URL/model")
if preset == "custom":
    set(preset=preset, api_key=ask_user("Enter API key"))
else:
    set(preset=preset)

# 4️⃣ Self‑test the configuration (guardrail)

selftest()

Round Limit Validation


# Example: Docket round limit enforcement (Docket skill)

MAX_ROUNDS = 3
current_round = docket_yaml["round"]
if current_round >= MAX_ROUNDS:
    raise RuntimeError("Maximum number of rounds exceeded – guardrail enforced.")

Summary

  • Explicit Activation: Guardrails remain dormant until the user explicitly requests the skill, as defined in the scope sections of each guardrails.md.
  • Data Sanitization: Skills are prohibited from ingesting unsanitized client data or emitting secrets like API keys.
  • Package Isolation: Cross-package interference is forbidden; skills cannot modify or invoke tools/ modules from other skill directories.
  • Configuration Verification: Vector-based retrieval requires successful execution of config.py and passing selftest() results before activation.
  • Controlled Output: Drafts stay internal under outputs/ subdirectories; Word documents export only after explicit user confirmation.
  • Interaction Limits: Docket coordination enforces a maximum of three rounds with phase transitions governed by phases.yaml.

Frequently Asked Questions

What triggers the activation of guardrails in the patent disclosure skill?

The guardrails activate only after an explicit user request, as stated in the scope sections (lines 5–10) of skills/patent-oa/prompts/guardrails.md. Until the user specifically invokes the skill—for example, by asking for Office Action draft assistance—the safety constraints remain optional and latent, preventing accidental execution.

How does the repository prevent API key leakage in prompt templates?

The 硬性禁止 (hard prohibition) rules in lines 13–20 of the OA guardrails explicitly forbid embedding or echoing API keys and other secrets. Additionally, the configuration workflow in config.py isolates key handling to initialization scripts rather than prompt templates, ensuring keys never appear in generated outputs or repository commits.

What is the maximum number of rounds allowed in docket coordination?

The docket skill enforces a maximum of three rounds per case, as specified in skills/patent-docket/prompts/guardrails.md (lines 11–18). Exceeding this limit raises a RuntimeError and terminates the interaction, preventing unbounded conversation loops during patent docket management.

Why must skills run config.py before using vector-based retrieval?

According to lines 25–36 of the OA guardrails, skills must verify their embedding configuration through config.py and selftest() to ensure that retrieval-augmented generation operates against properly initialized and tested vector stores. This prevents hallucinated or corrupted results from unsanitized retrieval hits.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →