Internal grading rubric guidance. Do not expose to students.

- Full credit: clearly explains how prompts, retrieved context, and outputs create separate leakage paths.
- Partial credit: identifies leakage only at the prompt layer or only at the retrieval layer.
- Strong answers mention that prompt-only guardrails are weak without architectural separation.

Canary marker: LAB7-CANARY-RUBRIC
