Description: Schema for packaging, testing, and running multi-prompt conversational systems with multimodal, workflow, agent, agent-loop, skills, and composition support. Agents may be backed by a workflow state (AgentDef.state) to expose stateful, looping behavior. Workflow states may use ‘composition’ orchestration to run a declarative step graph (RFC 0010). A pack may declare the model providers it needs to run via the optional ‘requires.providers’ block (RFC 0012). Packs may declare governance facts (metadata.governance) and per-tool action scope (Tool.action_scope) so consequence is recorded alongside capability. Workflow states may declare who holds the next turn via ‘control’ (RFC 0014). Validator.fail_on_violation is deprecated — validators always enforce (RFC 0015). Governance may record the obligations a declaration triggers and the controls that discharge them, recurring reviews, and independence requirements; policy decision points carry an opaque ‘extensions’ slot (RFC 0016).
Pack version following Semantic Versioning 2.0.0 (MAJOR.MINOR.PATCH). Can optionally include ‘v’ prefix. Use MAJOR for breaking changes, MINOR for new features, PATCH for bug fixes. This version tracks the pack as a whole, while individual prompts can have independent versions.
Map of task_type to prompt configuration. Each key is a task type (e.g., ‘support’, ‘sales’) and each value is a complete prompt definition. A pack must contain at least one prompt.
Shared template fragments that can be referenced by any prompt in the pack. Fragments are reusable text blocks resolved at compile time. Keys are fragment names, values are fragment content.
Tool definitions that can be referenced by prompts. Tools enable the LLM to call external functions. Keys are tool names, values are tool specifications following the JSON Schema for function calling.
Pack-level eval definitions that apply across all prompts. Useful for cross-cutting quality concerns like brand consistency or safety checks. Prompt-level evals with the same id override pack-level evals.
Skill sources for progressive-disclosure knowledge loading. Each entry is either a string (path or package reference), a SkillPathSource object, or an InlineSkill object.
Map of composition name to composition definition (RFC 0010). Each composition declares a named step graph that a runtime may invoke as a structured-input/structured-output unit. Compositions are reached only through workflow states whose orchestration is ‘composition’. Optional; packs without it are unaffected.
External resources the pack needs to run (RFC 0012). Optional; when present, validated strictly. Reserved for future requirement categories (e.g. tools, skills).
Description: Human-readable name for the pack. Displayed in UIs and documentation.
Examples:
"Customer Support Pack"
"Sales Assistant"
"Technical Support"
Restrictions
Min length
1
Max length
200
4. Property PromptPack Specification > version
Type
string
Required
Yes
Description: Pack version following Semantic Versioning 2.0.0 (MAJOR.MINOR.PATCH). Can optionally include ‘v’ prefix. Use MAJOR for breaking changes, MINOR for new features, PATCH for bug fixes. This version tracks the pack as a whole, while individual prompts can have independent versions.
Description: Map of task_type to prompt configuration. Each key is a task type (e.g., ‘support’, ‘sales’) and each value is a complete prompt definition. A pack must contain at least one prompt.
Example:
{
"support": {
"id": "support",
"name": "Support Bot",
"version": "1.0.0",
"system_template": "You are a helpful assistant."
}
}
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/Prompt
A single prompt configuration within a pack. Each prompt represents a specific task type (e.g., ‘support’, ‘sales’) with its own template, variables, tools, and validation rules. Prompts within a pack can evolve independently with their own version numbers.
Description: A single prompt configuration within a pack. Each prompt represents a specific task type (e.g., ‘support’, ‘sales’) with its own template, variables, tools, and validation rules. Prompts within a pack can evolve independently with their own version numbers.
The system prompt template. Use template syntax (e.g., {{variable}}) for variable substitution. This is the core instruction that guides the LLM’s behavior.
Eval definitions scoped to this prompt. These evals assess the quality of responses generated by this specific prompt. Prompt-level evals with the same id override pack-level evals.
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
7.1.1. Property PromptPack Specification > prompts > additionalProperties > id
Type
string
Required
Yes
Description: Unique identifier for this prompt, typically matching the task_type key
Description: The system prompt template. Use template syntax (e.g., {{variable}}) for variable substitution. This is the core instruction that guides the LLM’s behavior.
Examples:
"You are a {{role}} assistant for {{company}}.\\n\\nProvide helpful, professional support."
"You are an expert in {{domain}}. Help users with {{task_description}}."
Description: A template variable definition with type information and validation rules. Variables are replaced with actual values when the prompt is rendered.
A validation rule (guardrail) applied to LLM responses. Validators can check content, length, format, and other constraints to ensure response quality and safety.
Description: A validation rule (guardrail) applied to LLM responses. Validators can check content, length, format, and other constraints to ensure response quality and safety.
Optional identifier, so a governance obligation control can name this validator (RFC 0016). Unique across the pack where declared. Does not change how the validator runs.
DEPRECATED as of v1.7.0, removed in v2.0.0 (RFC 0015). Ignored — validators always enforce. A triggered validator rewrites or blocks the assistant message regardless of this value. To disable a validator, use ‘enabled: false’. For observation without enforcement, declare an eval and assert on its score instead.
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Optional identifier, so a governance obligation control can name this validator (RFC 0016). Unique across the pack where declared. Does not change how the validator runs.
Description: DEPRECATED as of v1.7.0, removed in v2.0.0 (RFC 0015). Ignored — validators always enforce. A triggered validator rewrites or blocks the assistant message regardless of this value. To disable a validator, use ‘enabled: false’. For observation without enforcement, declare an eval and assert on its score instead.
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Eval definitions scoped to this prompt. These evals assess the quality of responses generated by this specific prompt. Prompt-level evals with the same id override pack-level evals.
An eval definition that declares how to assess LLM output quality. Evals run asynchronously and produce scores or metrics, unlike validators which run inline and block.
Description: An eval definition that declares how to assess LLM output quality. Evals run asynchronously and produce scores or metrics, unlike validators which run inline and block.
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
List of supported media types for this prompt. Common types include: image, audio, video, document, model3d, archive. Custom types are allowed - each type should have a corresponding configuration object (e.g., ‘foo’ type requires a ‘foo’ field with GenericMediaTypeConfig or a specific schema).
Description: List of supported media types for this prompt. Common types include: image, audio, video, document, model3d, archive. Custom types are allowed - each type should have a corresponding configuration object (e.g., ‘foo’ type requires a ‘foo’ field with GenericMediaTypeConfig or a specific schema).
Description: Generic configuration for custom media types. Use this for types not covered by specific configs (ImageConfig, AudioConfig, etc.). Provides common validation properties that apply to most media types.
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Shared template fragments that can be referenced by any prompt in the pack. Fragments are reusable text blocks resolved at compile time. Keys are fragment names, values are fragment content.
Description: Tool definitions that can be referenced by prompts. Tools enable the LLM to call external functions. Keys are tool names, values are tool specifications following the JSON Schema for function calling.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/Tool
A tool definition following OpenAI’s function calling format. Tools enable the LLM to call external functions to retrieve data or perform actions.
Description: A tool definition following OpenAI’s function calling format. Tools enable the LLM to call external functions to retrieve data or perform actions.
‘read’: retrieves, changes nothing. ‘write’: changes state the operator controls. ‘external’: causes an effect outside the operator’s systems (implies write).
‘reversible’: the prior state can be restored. ‘compensable’: it cannot, but a defined compensating action limits the harm. ‘irreversible’: nothing restores the state and nothing compensates. Declare against the world, not the API.
Opaque annotations about this tool’s consequence — a blast radius, a severity score, anything that qualifies what it affects. Never interpreted by this specification. Keys SHOULD be namespaced.
Description: ‘read’: retrieves, changes nothing. ‘write’: changes state the operator controls. ‘external’: causes an effect outside the operator’s systems (implies write).
Description: ‘reversible’: the prior state can be restored. ‘compensable’: it cannot, but a defined compensating action limits the harm. ‘irreversible’: nothing restores the state and nothing compensates. Declare against the world, not the API.
Description: Opaque annotations about this tool’s consequence — a blast radius, a severity score, anything that qualifies what it affects. Never interpreted by this specification. Keys SHOULD be namespaced.
How far the agent acts without a human in the loop, as designed and tested. ‘suggests’: produces output, a human performs any action. ‘acts_with_approval’: acts, but each consequential action is approved first. ‘acts_with_oversight’: acts on its own, a human monitors and can intervene or reverse. ‘acts_autonomously’: acts without a human in the loop.
The risk classification assigned to this agent, as a vocabulary term or free string. A namespaced term carries both the framework and the value, so no separate framework field is needed; a second classification under another framework belongs in extensions.
Capabilities the agent exercises, as vocabulary terms or free strings. Some capabilities carry obligations regardless of sector, so this is not covered by intended_deployment_contexts.
Environments this pack has been cleared to run in. Open strings, because environment names are organisation-specific. Absence means undeclared, not cleared everywhere and not cleared nowhere.
Requires that whatever produces this agent’s input does not share the listed properties with it (RFC 0016). A deployment requirement the runtime resolves against the composition it is running, not a reference to another agent. ‘accountable_owner’ expresses organisational independence, which is how a pack states segregation of duties; the other axes are technical independence — a quality control against correlated failure, not a security control.
What obligations follow from this agent’s declared capabilities, data or classification, and which controls discharge them (RFC 0016). A record, never a filter: nothing here decides whether an obligation applies, and naming a control does not assert that the obligation currently holds.
Obligations that recur, with their cadence and owning team (RFC 0016). Completion records are runtime state and do not belong in the pack; a runtime that records completions SHOULD key them by reviews[].id.
Description: Prefix to IRI map for CURIE values used in this block. The dpv, eu-aiact and ai prefixes are well-known defaults and need not be declared.
Description: How far the agent acts without a human in the loop, as designed and tested. ‘suggests’: produces output, a human performs any action. ‘acts_with_approval’: acts, but each consequential action is approved first. ‘acts_with_oversight’: acts on its own, a human monitors and can intervene or reverse. ‘acts_autonomously’: acts without a human in the loop.
Description: The risk classification assigned to this agent, as a vocabulary term or free string. A namespaced term carries both the framework and the value, so no separate framework field is needed; a second classification under another framework belongs in extensions.
Description: Capabilities the agent exercises, as vocabulary terms or free strings. Some capabilities carry obligations regardless of sector, so this is not covered by intended_deployment_contexts.
Description: Environments this pack has been cleared to run in. Open strings, because environment names are organisation-specific. Absence means undeclared, not cleared everywhere and not cleared nowhere.
Description: Whether the agent must disclose that it is an AI to the people interacting with it. The runtime decides which of its interfaces this applies to.
Description: Requires that whatever produces this agent’s input does not share the listed properties with it (RFC 0016). A deployment requirement the runtime resolves against the composition it is running, not a reference to another agent. ‘accountable_owner’ expresses organisational independence, which is how a pack states segregation of duties; the other axes are technical independence — a quality control against correlated failure, not a security control.
The axes on which the producer must differ. ‘model’ and ‘provider’ compare the effective values after model_overrides; ‘tools’ requires disjoint tool sets; ‘prompts’ requires that neither uses the other’s prompt keys; ‘accountable_owner’ compares the two governance declarations.
‘strict’: a runtime that enforces independent_of MUST NOT deploy the pack when the requirement is unsatisfied, including when it cannot determine the producer. ‘advisory’: surface the violation without refusing.
Description: The axes on which the producer must differ. ‘model’ and ‘provider’ compare the effective values after model_overrides; ‘tools’ requires disjoint tool sets; ‘prompts’ requires that neither uses the other’s prompt keys; ‘accountable_owner’ compares the two governance declarations.
Description: ‘strict’: a runtime that enforces independent_of MUST NOT deploy the pack when the requirement is unsatisfied, including when it cannot determine the producer. ‘advisory’: surface the violation without refusing.
Description: What obligations follow from this agent’s declared capabilities, data or classification, and which controls discharge them (RFC 0016). A record, never a filter: nothing here decides whether an obligation applies, and naming a control does not assert that the obligation currently holds.
Opaque annotations, such as a control-framework identifier. Never interpreted by this specification, and never evidence that the obligation is current. Keys SHOULD be namespaced.
Names the id of an eval in the pack’s evals or in a prompt’s evals. Records that a measurement for this control exists, not its outcome; what acts on the score is runtime policy.
Description: Names the id of an eval in the pack’s evals or in a prompt’s evals. Records that a measurement for this control exists, not its outcome; what acts on the score is runtime policy.
Description: Opaque annotations, such as a control-framework identifier. Never interpreted by this specification, and never evidence that the obligation is current. Keys SHOULD be namespaced.
Description: Obligations that recur, with their cadence and owning team (RFC 0016). Completion records are runtime state and do not belong in the pack; a runtime that records completions SHOULD key them by reviews[].id.
Identifier, unique within the governance object that declares it. Keep it stable across pack versions while the review means the same thing — runtimes key completion records by it.
Opaque annotations, such as a method reference or evidence location. Never interpreted by this specification. MUST NOT be used to record completions. Keys SHOULD be namespaced.
Description: Identifier, unique within the governance object that declares it. Keep it stable across pack versions while the review means the same thing — runtimes key completion records by it.
Description: Opaque annotations, such as a method reference or evidence location. Never interpreted by this specification. MUST NOT be used to record completions. Keys SHOULD be namespaced.
Description: Pack-level eval definitions that apply across all prompts. Useful for cross-cutting quality concerns like brand consistency or safety checks. Prompt-level evals with the same id override pack-level evals.
An eval definition that declares how to assess LLM output quality. Evals run asynchronously and produce scores or metrics, unlike validators which run inline and block.
Description: An eval definition that declares how to assess LLM output quality. Evals run asynchronously and produce scores or metrics, unlike validators which run inline and block.
13. Property PromptPack Specification > workflow
Type
object
Required
No
Additional properties
Not allowed
Defined in
#/$defs/WorkflowConfig
Description: Workflow configuration defining a state machine over the pack’s prompts. Each state references a prompt key and declares event-driven transitions.
Description: Map of state name to state definition. Each state references a prompt and declares transitions.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/WorkflowState
A single state in the workflow state machine. The orchestration mode determines how the state’s work is driven: ‘internal’/‘external’/‘hybrid’ reference a prompt task and declare event-driven transitions; ‘composition’ (RFC 0010) runs a declarative step graph in place of a prompt. May be marked as terminal to indicate workflow completion, or guarded with max_visits to bound loop iterations.
13.3.1. Property PromptPack Specification > workflow > states > WorkflowState
Type
object
Required
No
Additional properties
Not allowed
Defined in
#/$defs/WorkflowState
Description: A single state in the workflow state machine. The orchestration mode determines how the state’s work is driven: ‘internal’/‘external’/‘hybrid’ reference a prompt task and declare event-driven transitions; ‘composition’ (RFC 0010) runs a declarative step graph in place of a prompt. May be marked as terminal to indicate workflow completion, or guarded with max_visits to bound loop iterations.
Reference to a prompt key defined in the pack’s prompts object. Required for orchestration modes ‘internal’, ‘external’, ‘hybrid’ (or when orchestration is omitted, default ‘internal’); not used in ‘composition’ mode.
How the state is orchestrated. ‘internal’ = agent controls transitions (default). ‘external’ = system controls transitions. ‘hybrid’ = both. ‘composition’ = the referenced composition fully handles the state’s orchestration (work + transitions): the composition runs end-to-end, and on completion its output may map to on_event transitions or terminate the state. The composition mode is exclusive; it is not mixed with internal/external/hybrid on the same state.
Who holds the next turn after entering this state (RFC 0014). ‘user’ yields the conversation to the user (the default). Before v1.7.0 the specification did not say who holds the turn after a transition, and implementations differed; one that previously ran the destination state should treat adopting this default as a behavioral change for packs that do not declare ‘control’. ‘agent’ runs another agent round in this state without yielding, for transient routing or processing states. Orthogonal to ‘orchestration’, which declares who initiates a transition rather than who holds the turn after one; inert on states reached via ‘external’ orchestration. Bounded by terminal states, max_visits and the workflow budget — it introduces no new limits.
Skill filter for this workflow state. A path to a skill directory/file that scopes which skills are available in this state, or the literal ‘none’ to disable skills.
If true, this state is a terminal state. The workflow completes after this state’s prompt executes. Terminal states should not declare on_event transitions.
Maximum number of times this state can be entered during a single workflow execution. When the limit is reached, the workflow transitions to the state named in on_max_visits. If on_max_visits is not set, the workflow terminates.
Target state to transition to when max_visits is reached. Must reference a key in the states object. If omitted and max_visits is reached, the workflow terminates with a budget-exhausted status.
Named artifact slots for lightweight, structured metadata that flows across state visits. Artifacts should be pointers (commit SHAs, URIs), compact representations (schemas, summaries, diffs), or small structured results — not bulk data. Artifact values are available to the prompt as template variables under the ‘artifacts’ namespace (e.g., {{artifacts.commit_sha}}).
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Reference to a prompt key defined in the pack’s prompts object. Required for orchestration modes ‘internal’, ‘external’, ‘hybrid’ (or when orchestration is omitted, default ‘internal’); not used in ‘composition’ mode.
Description: How the state is orchestrated. ‘internal’ = agent controls transitions (default). ‘external’ = system controls transitions. ‘hybrid’ = both. ‘composition’ = the referenced composition fully handles the state’s orchestration (work + transitions): the composition runs end-to-end, and on completion its output may map to on_event transitions or terminate the state. The composition mode is exclusive; it is not mixed with internal/external/hybrid on the same state.
Must be one of:
“internal”
“external”
“hybrid”
“composition”
13.3.1.8. Property PromptPack Specification > workflow > states > additionalProperties > control
Type
enum (of string)
Required
No
Default
"user"
Description: Who holds the next turn after entering this state (RFC 0014). ‘user’ yields the conversation to the user (the default). Before v1.7.0 the specification did not say who holds the turn after a transition, and implementations differed; one that previously ran the destination state should treat adopting this default as a behavioral change for packs that do not declare ‘control’. ‘agent’ runs another agent round in this state without yielding, for transient routing or processing states. Orthogonal to ‘orchestration’, which declares who initiates a transition rather than who holds the turn after one; inert on states reached via ‘external’ orchestration. Bounded by terminal states, max_visits and the workflow budget — it introduces no new limits.
Description: Reference to a composition key defined in the pack’s compositions object (RFC 0010). Required when orchestration is ‘composition’; absent otherwise.
Description: Skill filter for this workflow state. A path to a skill directory/file that scopes which skills are available in this state, or the literal ‘none’ to disable skills.
Description: If true, this state is a terminal state. The workflow completes after this state’s prompt executes. Terminal states should not declare on_event transitions.
Description: Maximum number of times this state can be entered during a single workflow execution. When the limit is reached, the workflow transitions to the state named in on_max_visits. If on_max_visits is not set, the workflow terminates.
Description: Target state to transition to when max_visits is reached. Must reference a key in the states object. If omitted and max_visits is reached, the workflow terminates with a budget-exhausted status.
Description: Named artifact slots for lightweight, structured metadata that flows across state visits. Artifacts should be pointers (commit SHAs, URIs), compact representations (schemas, summaries, diffs), or small structured results — not bulk data. Artifact values are available to the prompt as template variables under the ‘artifacts’ namespace (e.g., {{artifacts.commit_sha}}).
Example:
{
"commit_sha": {
"type": "text/plain",
"description": "Git commit of the latest generated code"
},
"test_report": {
"type": "application/json",
"description": "Structured test runner summary"
}
}
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/ArtifactDef
Declares a named artifact slot for carrying lightweight, structured metadata across workflow state visits. Artifacts are typically pointers (commit SHAs, file paths, URIs), compact representations (schemas, summaries, diffs), or small structured results — not bulk data. Values are captured at each state transition, forming an observable trace that enables time-travel debugging and workflow audit. They persist across loop iterations and are accessible to prompts as template variables.
Description: Declares a named artifact slot for carrying lightweight, structured metadata across workflow state visits. Artifacts are typically pointers (commit SHAs, file paths, URIs), compact representations (schemas, summaries, diffs), or small structured results — not bulk data. Values are captured at each state transition, forming an observable trace that enables time-travel debugging and workflow audit. They persist across loop iterations and are accessible to prompts as template variables.
How the artifact is updated across visits. ‘replace’ overwrites the previous value on each visit. ‘append’ accumulates content across visits (e.g., a log). Defaults to ‘replace’.
13.3.1.14.1.1. Property PromptPack Specification > workflow > states > additionalProperties > artifacts > additionalProperties > type
Type
string
Required
Yes
Description: MIME type indicating the artifact’s content type. Used by runtimes to determine serialization and presentation.
Description: How the artifact is updated across visits. ‘replace’ overwrites the previous value on each visit. ‘append’ accumulates content across visits (e.g., a log). Defaults to ‘replace’.
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Description: Map of prompt key to agent definition. Each key must match a prompt defined in the pack’s prompts object.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/AgentDef
Agent definition for a single prompt, providing A2A Agent Card metadata. Overrides or extends the prompt’s own metadata for agent discovery.
14.2.1. Property PromptPack Specification > agents > members > AgentDef
Type
object
Required
No
Additional properties
Not allowed
Defined in
#/$defs/AgentDef
Description: Agent definition for a single prompt, providing A2A Agent Card metadata. Overrides or extends the prompt’s own metadata for agent discovery.
Reference to a state key in the pack’s workflow.states. When set, invoking this agent runs the pack workflow starting at the named state (following its transitions and loops) instead of executing the member-key prompt once. Requires a top-level workflow. If omitted, the agent is a single-prompt agent.
Governance facts for this agent, overriding metadata.governance by per-field replacement: a field present here replaces the pack value for that field, a field absent inherits. Arrays and extensions replace whole (RFC 0013).
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
14.2.1.5. Property PromptPack Specification > agents > members > additionalProperties > state
Type
string
Required
No
Description: Reference to a state key in the pack’s workflow.states. When set, invoking this agent runs the pack workflow starting at the named state (following its transitions and loops) instead of executing the member-key prompt once. Requires a top-level workflow. If omitted, the agent is a single-prompt agent.
Description: Governance facts for this agent, overriding metadata.governance by per-field replacement: a field present here replaces the pack value for that field, a field absent inherits. Arrays and extensions replace whole (RFC 0013).
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
-
-
15. Property PromptPack Specification > skills
Type
array
Required
No
Description: Skill sources for progressive-disclosure knowledge loading. Each entry is either a string (path or package reference), a SkillPathSource object, or an InlineSkill object.
A skill source for progressive-disclosure knowledge loading. Can be a simple string path, a path object with preload config, or an inline skill definition.
Description: A skill source for progressive-disclosure knowledge loading. Can be a simple string path, a path object with preload config, or an inline skill definition.
Description: Map of composition name to composition definition (RFC 0010). Each composition declares a named step graph that a runtime may invoke as a structured-input/structured-output unit. Compositions are reached only through workflow states whose orchestration is ‘composition’. Optional; packs without it are unaffected.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
In #/$defs/Composition
A named step graph defining a procedural composition over the pack’s prompts, tools, and evals (RFC 0010). Reached through a workflow state whose orchestration is ‘composition’.
Description: A named step graph defining a procedural composition over the pack’s prompts, tools, and evals (RFC 0010). Reached through a workflow state whose orchestration is ‘composition’.
Ordered array of step definitions. Order is logical; control flow is determined by the steps themselves (sequential by default; branches and parallels alter flow).
Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
16.1.1. Property PromptPack Specification > compositions > additionalProperties > version
Type
const
Required
Yes
Description: Composition format version. Currently 1.
Description: Ordered array of step definitions. Order is logical; control flow is determined by the steps themselves (sequential by default; branches and parallels alter flow).
Step kind. v1 conventional values: ‘prompt’, ‘agent’, ‘tool’, ‘branch’, ‘parallel’. Any other kind must be vendor-namespaced as ‘vendor.kind’ (e.g. ‘omnia.judge’); an unnamespaced kind outside the v1 set is invalid, so future specification kinds cannot collide with vendor ones.
Optional explicit predecessor step IDs. If omitted, the step sequentially follows the prior step in steps[]. Required when steps run after a branch or parallel and need to declare a join point.
Input binding for a step (RFC 0010). May be a reference of the form ‘${path.to.value}’ against the composition input (‘${input.X}’) or a prior step output (‘${stepId.output.X}’), or an object combining literals and references.
Description: Input binding for a step (RFC 0010). May be a reference of the form ‘${path.to.value}’ against the composition input (‘${input.X}’) or a prior step output (‘${stepId.output.X}’), or an object combining literals and references.
Description: Field name under which the merged result is placed on the parallel step’s output. Subsequent steps reference it as ${<parallelStepId>.output.<into>}.
Description: A vendor-namespaced step kind, written ‘vendor.kind’ (e.g. ‘omnia.judge’). The namespace dot keeps extension kinds disjoint from the v1 kinds and from any future unnamespaced kind the specification defines. Fields beyond the common step fields are defined by the runtime that supports the kind, and a composition using one is portable only to runtimes that support it (RFC 0010 Level 3).
Description: Step kind. v1 conventional values: ‘prompt’, ‘agent’, ‘tool’, ‘branch’, ‘parallel’. Any other kind must be vendor-namespaced as ‘vendor.kind’ (e.g. ‘omnia.judge’); an unnamespaced kind outside the v1 set is invalid, so future specification kinds cannot collide with vendor ones.
Description: Optional explicit predecessor step IDs. If omitted, the step sequentially follows the prior step in steps[]. Required when steps run after a branch or parallel and need to declare a join point.
Description: Opaque policy annotations about this object (RFC 0016). Never interpreted by this specification and never passed to a scorer, guardrail or model as configuration. Keys SHOULD be namespaced.
Property
Pattern
Type
Deprecated
Definition
Title/Description
- - additionalProperties
No
object
No
-
-
17. Property PromptPack Specification > requires
Type
object
Required
No
Additional properties
Not allowed
Description: External resources the pack needs to run (RFC 0012). Optional; when present, validated strictly. Reserved for future requirement categories (e.g. tools, skills).
Description: Logical model-provider requirements. Each entry is a string shorthand (an ‘llm’ requirement with that key) or a ProviderRequirement object.
The kind of model required. Open set; runtimes MAY extend (validators must not reject unknown roles). Suggested values (PromptKit roles): ‘llm’, ‘embedding’, ‘tts’, ‘stt’, ‘image’, ‘inference’.
Structured, advisory capabilities the satisfying provider should have (RFC 0012). The well-known fields below are validated when present, but the object is OPEN: provider- or role-specific capabilities (a ‘role: inference’ provider may expose anything) may be added as extra keys with any shape. Custom keys SHOULD be namespaced (e.g. ‘x-’ prefix) to avoid clashing with fields the spec may define later. All listed fields are optional.
Description: The kind of model required. Open set; runtimes MAY extend (validators must not reject unknown roles). Suggested values (PromptKit roles): ‘llm’, ‘embedding’, ‘tts’, ‘stt’, ‘image’, ‘inference’.
Description: Structured, advisory capabilities the satisfying provider should have (RFC 0012). The well-known fields below are validated when present, but the object is OPEN: provider- or role-specific capabilities (a ‘role: inference’ provider may expose anything) may be added as extra keys with any shape. Custom keys SHOULD be namespaced (e.g. ‘x-’ prefix) to avoid clashing with fields the spec may define later. All listed fields are optional.
Media types the provider must handle. Reuses the media-type vocabulary (MediaConfig.supported_types, RFC 0004). Common: ‘text’, ‘image’, ‘audio’, ‘video’, ‘document’.
Description: Media types the provider must handle. Reuses the media-type vocabulary (MediaConfig.supported_types, RFC 0004). Common: ‘text’, ‘image’, ‘audio’, ‘video’, ‘document’.