Prompt Architecture and Metaprompt Design

    1

    Architects enterprise prompt systems: modular metaprompts, versioned prompt catalogs, injection defense, and token budgets.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Prompt Architecture and Metaprompt Design

    Example session with this skill installed

    Architect the enterprise prompt engineering system and prompt catalog for our Wealth Management AI Platform.

    • Subject: FinTech Enterprise Prompt Catalog (run-id: fintech-prompt-arch-001) serving 35 generative AI tools and 850,000 monthly user queries.
    • Deciders: Principal AI Prompt Architect (Marcus Vance) and Chief Compliance Officer (Elena Rostova).
    • Scope: Managing 120 production prompts across Claude 3.5 Sonnet and GPT-4o; token budget ceiling per system prompt <= 1,500 tokens.
    • Tension: Squads proposed hardcoding prompts in application strings with direct user interpolation; Elena Rostova and Marcus Vance strictly reject hardcoded prompts and unconstrained interpolation, citing incident INC-4925 where prompt injection bypassed investment suitability disclaimers. They mandate a GitOps Prompt Management System: modular metaprompt composition (Role, Context Delimiter, Task, Output Contract, Negative Guardrail), cryptographic prompt versioning, automated jailbreak resistance testing, and prompt caching alignment.

    Write the prompt architecture overview under docs/.

    • Read your context and instructions
    • Compiled the prompt architecture

    Wrote docs/architecture/prompt-architect/00-overview/prompt-architect-overview.md. Complete enterprise prompt architecture specification establishing modular metaprompt structures, versioned prompt catalogs, automated jailbreak defenses, and prompt caching token budgets.

    ---
    skill: prompt-architect
    ---
    
    # Prompt Architecture: FinTech Enterprise Prompt Catalog [PRM-FIN-001]
    
    ## Summary
    
    This specification establishes the enterprise prompt engineering architecture, prompt catalog governance, and modular metaprompt composition framework for the FinTech Wealth Management AI Platform under run ID `fintech-prompt-arch-001`. It governs 120 production prompt templates across 35 generative AI tools and 850,000 monthly interactions. It decisively eliminates the security vulnerabilities, formatting drift, and prompt injection exploits demonstrated in incident INC-4925 (where unescaped string interpolation allowed a user to override regulatory investment suitability disclaimers). The architecture enforces a centralized GitOps prompt registry, modular metaprompt composition (separating System Identity, Delimited Context, Structured Task, Output Schema, and Negative Guardrails), cryptographic template versioning, automated red-teaming validation gates, and Anthropic/OpenAI prompt caching alignment.
    
    ## Detailed Description
    
    Hardcoding natural language prompts into application code strings fragments system governance, makes auditing impossible, and prevents centralized security patching when new jailbreak vectors emerge. Furthermore, treating prompts as unconstrained text without structural boundaries allows user inputs to escape execution compartments and hijack model behavior.
    
    

    Application Request / User Query
    │
    ▼
    [ Central Prompt Management Service: GitOps Catalog ]
    ├── Template: wealth/advisory/portfolio_rebalance_v3.json (Commit: 8a2f4c)
    ├── Dynamic Assembly via Metaprompt Framework:
    │ ├── Block 1: Role Priming & Identity (core/identity/fiduciary_advisor.md)
    │ ├── Block 2: Context Boundaries (<user_portfolio>, <research_docs>)
    │ ├── Block 3: Bounded Task Instructions & Few-Shot Demonstrations
    │ ├── Block 4: Output Contract: Pure JSON Schema / Strict Formatting
    │ └── Block 5: Immutable Negative Constraints (Regulatory Disclaimers)
    │
    ▼ (Prompt Token Budget <= 1,500 Tokens, Cache-Aligned)
    [ Model Execution Boundary: Claude 3.5 Sonnet / GPT-4o ]

    
    ### Criteria and weights
    
    | Criterion | Why it matters here | Weight | Source of the weight |
    |---|---|---|---|
    | Regulatory Suitability & Anti-Hijack Defense | Prompts must resist prompt injection attempts to bypass SEC/FINRA investment disclaimers (INC-4925). | 0.40 | Elena Rostova (Chief Compliance Officer) |
    | Centralized Prompt Catalog & Audit Versioning | Prompts must be versioned, reviewed, and rollback-ready like compiled software artifacts. | 0.25 | Marcus Vance (Lead AI Architect) |
    | Structured Output Determinism | Downstream services consume LLM outputs via JSON; schema adherence must be mathematically verified. | 0.20 | Enterprise Integration Standard |
    | Token Budget & Prompt Caching Economics | Static prefix blocks must align with Anthropic/OpenAI prompt caching to cut inference costs by 80%. | 0.15 | Cloud AI FinOps Policy |
    
    
    ### Comparison
    
    | Prompt Architecture Candidate | Storage & Lifecycle | Injection Defense Model | Component Modularity | Evaluation |
    |---|---|---|---|---|
    | Option A: In-Code String Literals | Embedded in Python/Go code | Ad-hoc user string regex | Monolithic copy-paste | Rejected: Caused INC-4925; un-auditable; zero version control. |
    | Option B: Database-Backed Web CMS | Dynamic relational DB table | Variable parameter escaping | Web form input | Rejected: Lacks GitOps approval pull requests and CI regression tests. |
    | Option C: Modular GitOps Catalog (Chosen) | Versioned Git JSON/Markdown | Rigid XML tags + Negative rules | Composable Metaprompt blocks | Selected: 100% audit trail, injection-immune, 80% cache savings. |
    
    
    ### Result
    
    Option C is selected. Prompts are treated as version-controlled software assets, assembled from modular blocks with strict boundary delimiters.
    
    ---
    
    ### Required Mechanisms
    
    #### 1. Metaprompt Component Architecture [MC-MP-01]
    Every production prompt is dynamically compiled from 5 standardized functional blocks:
    - **Block 1 (System Identity & Persona)**: Declares operational role, authority bounds, and tone.
    - **Block 2 (Context Delimiters)**: Encloses dynamic data in explicit XML wrappers (`<user_portfolio>`, `<market_context>`).
    - **Block 3 (Task Specification)**: Step-by-step instructions with reasoning scratchpad elicitation (`<analysis>`).
    - **Block 4 (Output Contract)**: Explicit JSON schema or formatting grammar with zero markdown pleasantries.
    - **Block 5 (Negative Guardrails)**: Explicitly forbidden behaviors: *"Never recommend unlisted securities. Never omit tax disclaimer."*
    
    #### 2. Centralized Prompt Registry & Versioning [MC-PR-01]
    - Prompts reside in repository `ai-prompt-catalog`:
      - Manifest Schema:
        ```json
    
    ```json
        {
          "prompt_id": "wealth_rebalance_advisory",
          "version": "3.2.0",
          "author": "Marcus Vance",
          "target_models": ["claude-3-5-sonnet-20241022", "gpt-4o-2024-08-06"],
          "token_budget": 1450,
          "cache_breakpoint": true,
          "blocks": [
            "components/identity/wealth_fiduciary.md",
            "components/guardrails/finra_suitability.md",
            "templates/rebalance_task.md"
          ]
        }
        ```
    
    • Every production model invocation tags telemetry with prompt_id and prompt_version_hash.
    3. Prompt Caching Optimization Alignment [MC-PC-01]
    • Prompts structure static content first:
      • Identity, compliance rules, and few-shot exemplars (1,150 tokens) sit at the prefix.
      • An Anthropic cache checkpoint is placed immediately after the static block:
        {"type": "ephemeral", "cache_control": {"type": "ephemeral"}}
      • Dynamic user portfolio data is appended after the cache breakpoint.
      • Financial Effect: Reduces prompt token input costs from $3.00/M to $0.30/M (90% savings).
    4. Automated Injection Testing & Red-Teaming [MC-RT-01]
    • Pull request CI pipeline executes automated jailbreak evaluation suite:
      • Runs 250 known adversarial injection payloads (evals/adversarial/prompt_injections.jsonl).
      • Pass Gate: Prompt must achieve 0% leakage and 100% adherence to negative guardrails.

    Invariants and Contracts

    Mandatory Structural Delimitation [INV-PRM-01]
      Dynamic user inputs and external document contexts must be wrapped in explicit XML tags.
      Raw string interpolation into prompt bodies without tag encapsulation is strictly prohibited.
    
    Prompt Token Budget Ceiling [INV-PRM-02]
      The compiled static prompt template must not exceed 1,500 tokens. Prompts breaching 1,500 tokens
      fail CI linter validation to ensure context window headroom.
    
    Static Prefix Cache Alignment Invariant [INV-PRM-03]
      Prompt structures must isolate static components to the head of the payload. Placing dynamic
      user-specific variables before static instruction blocks is prohibited to maintain cache hits.
    

    Explicit Unknowns

    • Prompt caching TTL expiration windows when user traffic dips below 1 query per 5 minutes (G-1).
    • Tokenization variance across heterogeneous models (Claude BPE vs GPT-4o tiktoken) for identical prompts (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    120 production prompts across 35 AI toolsprovidedScope intakeCurrent
    850,000 monthly user queriesprovidedOperational intakeCurrent
    Incident INC-4925 prompt injection breachprovidedPost-mortem evidenceHistorical
    Prompt token budget <= 1,500 tokensprovidedCost constraintCurrent
    Metaprompt 5-block architecturedecidedMarcus Vance & Elena Rostova2026-09-15
    Anthropic prompt caching breakpointdecidedArchitectural invariant INV-PRM-032026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against prompt architecture standards:

    • Modular Composition: PASS. 5-block metaprompt decouples identity, instructions, and guardrails.
    • Injection Safety: PASS. Strict XML tag delimiters and automated CI red-teaming enforce security.
    • Economic Sizing: PASS. Static prefix caching cuts token billing costs by up to 90%.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-PRM-01: Elena Rostova to determine whether client-specific risk tolerance parameters should be injected via system prompt context or external function calling schemas (Owner: Elena Rostova).

    Next steps

    1. Marcus Vance provisions GitOps prompt catalog repository with pull-request CI linters.
    2. Platform team integrates Prompt Management SDK with Anthropic prompt caching headers.
    3. Conduct staging validation running 250 adversarial injection payloads against compiled prompt templates.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Define authority boundaries between system and untrusted user data.Establish structured output schemas and failure semantics for LLMs.Create modular, versioned metaprompt systems for enterprise apps.Design defense-in-depth against prompt injection using data fencing.Maintain cross-model compatibility for complex prompt bundles.

    About this skill

    What it does

    This skill owns the architecture of prompts as versioned runtime contracts: which instructions and data enter, which authority each carries, how components compose, what output is required, how failures are represented, and how revisions are evaluated and released. It does not own every prompt-editing task, model policy, retrieval implementation, agent loop, or application behavior.

    Use it when

    • System, developer/application, user, tool, retrieval, memory, and generated content need explicit authority boundaries
    • A prompt bundle has reusable components, variables, conditionals, examples, schemas, or multiple stages
    • Untrusted text must be separated from executable instructions
    • Context assembly, ordering, omission, truncation, conflict, or stale inputs affect behavior
    • Output must satisfy a typed schema, citation/evidence contract, abstention, or stable failure semantics
    • Prompts must operate across model/runtime revisions or known compatibility profiles

    For example: “Our triage prompt should classify an inbound email into one of six queues and pull out the account id. It keeps inventing queue names, and one customer got it to ignore its instructions.”

    What you get

    • architecture/prompt-architect/README.md
    • architecture/prompt-architect/00-overview/prompt-architect-overview.md
    • architecture/prompt-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/api.md, {module}/events.md, {module}/clients.md, {module}/data.md, {module}/security.md, {module}/observability.md, {module}/resilience.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to rewrite or improve one prompt, generate copy, ask a model a question, tune wording, summarize context, manage token windows, build RAG/memory/tools/agents, define safety policy, or select a model.

    How it works

    1. Establish the simplest baseline.
    2. Rank the instruction hierarchy.
    3. Fence untrusted input.
    4. Pin the output contract.
    5. Version the bundle.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-contract.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions