Yep - we do not expose any sort of prompting. We use the LLM only at specific parts of the process, and the user has no access to it.
There are multiple parsing and rule-based steps done to the input schemas - we extract specific pieces from the schemas and convert them to our internal format before feeding it our models. Thus, it mitigates such malicious behavior.