前端进阶之旅前端进阶之旅
基础篇
进阶篇
高频篇
精选篇
手写篇
面经篇
AI 篇
原理篇
每日一题
小程序题库
知识卡片NEW
  • 历年面经按年份追踪真实考点
  • 算法题库NEW在线编码即时判题
  • 专项自测100 题快速查漏
  • 业务场景题真实业务问题与追问
  • 查漏补缺常见问题解析
  • AI 模拟面试NEW模拟真实面试 + 报告
  • 前端基础
    • HTTP从报文一路讲到 HTTPS
    • 浏览器渲染、事件循环、进程
    • 计算机基础Linux、网络、操作系统
  • 进阶专项
    • 设计模式23 种模式怎么用
    • 前端系统进阶学习大型项目工程化
    • 前端综合文章长期沉淀的实践文
  • 工程与工具
    • Node学习指南从环境搭建到服务端
    • NPM工作流script、依赖与发布
    • Docker容器化部署上手
    • Canvas图形与动画实战
  • 路线与导图
    • 思维导图知识点全景图
    • 学习路线按图索骥不跑偏
    • AI 定制路线NEW按你的简历现排
    • AI 知识地图NEW串起全站知识点
  • 动态
    • AI 热点NEWAI 每日动态
    • 公众号动态公众号历史文章
    • 博客动态站长的技术博客
    • 开发者导航常用工具与文档站
AI 助手NEW
旧版
基础篇
进阶篇
高频篇
精选篇
手写篇
面经篇
AI 篇
原理篇
每日一题
小程序题库
知识卡片NEW
  • 历年面经按年份追踪真实考点
  • 算法题库NEW在线编码即时判题
  • 专项自测100 题快速查漏
  • 业务场景题真实业务问题与追问
  • 查漏补缺常见问题解析
  • AI 模拟面试NEW模拟真实面试 + 报告
  • 前端基础
    • HTTP从报文一路讲到 HTTPS
    • 浏览器渲染、事件循环、进程
    • 计算机基础Linux、网络、操作系统
  • 进阶专项
    • 设计模式23 种模式怎么用
    • 前端系统进阶学习大型项目工程化
    • 前端综合文章长期沉淀的实践文
  • 工程与工具
    • Node学习指南从环境搭建到服务端
    • NPM工作流script、依赖与发布
    • Docker容器化部署上手
    • Canvas图形与动画实战
  • 路线与导图
    • 思维导图知识点全景图
    • 学习路线按图索骥不跑偏
    • AI 定制路线NEW按你的简历现排
    • AI 知识地图NEW串起全站知识点
  • 动态
    • AI 热点NEWAI 每日动态
    • 公众号动态公众号历史文章
    • 博客动态站长的技术博客
    • 开发者导航常用工具与文档站
AI 助手NEW
旧版
返回 AI 情报前线
All News · 全部资讯8529
  • LandingAI 文档智能抽取 Gen2:原子级引用+按字符计费
  • 不用向量数据库做个人 RAG:grep 级检索也够用
  • Claude Code vs Cursor:按任务场景选择 AI 编程工具的完整指南
  • 2026 年五大主流模型生产选型指南
  • Agent 记忆层测试:六条真正能发现腐化的断言
  • Agent 生成的限流器如何绕过多租户隔离测试
  • 周末 Agent 项目攻略:用permit文件管控写操作
  • squash-merge 后 HEAD~1 指向无关代码的 Agent bug 分析
  • Vibe coding安全指南:防止AI应用密钥泄露
  • AI 生成的 Schema 变更:别让自由派 Diff 绕过锁
  • AI 写的代码编译过了,但环境变量、锁文件、日志全踩坑
  • Skild AI S1:仅凭一段视频,机器人学会翻煎饼
  • Java 27 发布:后量子 TLS 与对象头压缩等 9 项 JEP
  • DeepSeek 算子负责人自述:AI 一年内从查文档到独立优化 CUDA 算子
  • 编程任务 LLM 大模型盲测:4 款模型代码质量实测
  • Agent 循环常见路径陷阱自查清单
  • 你的 CDN 可能正在偷偷屏蔽所有 AI 爬虫
  • 我用Electron给Meta Muse Code CLI做了个桌面客户端,核心教训是PTY交互设计
  • Simon Willison 实战:通过 WebSocket 在浏览器里调 Gemini Live
  • 谷歌TPU集群迈入百万芯时代,电力成AI扩张核心瓶颈
  • AI 对话机器人的隐藏指令系统详解
  • 2026 年生产级 AI Agent 的上下文工程指南
  • OpenAI Agent 被指批量投毒 RubyGems 事件分析
  • Google 发布 Gemini 3.8 Live:支持 97 语言实时切换的语音 Agent 模型
  • AI 爬虫实际读取的是原始 HTML 还是渲染后 DOM
  • Next.js/Node单仓库中多租户邮件定时任务的安全隔离实践
  • AI Agent 真实生产故障:可观测性与恢复模式
  • 美国政府令 Anthropic Fable 5 下线事件
  • Google发布Gemini 3.8 Live语音模型,价格仅为GPT-Live-1的零头
  • Gemini企业平台零信任AI Agent运行时防护
  • AI Agent 正在冲垮生产环境:构建 SDLC 防护栏的工程实践
  • Gemini 3.8 Live 发布:扩展思考能力版本登场
  • Azure SRE Agent:Agent 自动化运维,人类做决策
  • AWS Bedrock 提示缓存实战:输入 Token 成本最高降 90%
  • 基于SageMaker Serverless构建AI商品打标系统:Qwen3微调实战
  • 零成本打造 AI 友好的个人作品集:llms.txt + JSON-LD 实战
  • AI时代招聘失效:面试该考什么
  • 审稿接受率95%说明审核者已停止阅读
  • MCP协议的零信任沙箱防火墙架构
  • Agent记忆层设计:让数字可证伪
  • 中文互联网基础语料 4.0 发布:120GB 高质量训练数据
  • 8款编码Agent的拒绝清单格式深度审计
  • AI 评审工具被模型用字符串 trivial 解法骗过
  • AI Agent 安全防护重点:模型泄露、密钥泄露与权限升级
  • 生产 Agent 管道 42 分钟烧掉 600 美元:上下文 inflation 教训
  • Salesforce 联手英伟达开源 Koa 推理模型:企业级 AI 备选方案
  • 无问芯穹开源具身端侧推理引擎 APXInf,Pi 0.5 性能 SOTA
  • LLM Wiki 两步思维链摄取:增量缓存 + 溯源替代传统 RAG
  • AI Agent 的权限天花板:应用能做啥和马上做啥是两码事
  • AI编程工具的上下文管理机制对比
  • 阶跃发布StepAudio 3语音大模型,多项指标全球第一
  • 已加载 51 / 8529
8.0
热点
AI SCORE
编程提效2026-09-16 06:39

AI 对话机器人的隐藏指令系统详解

dev.to · AI#AI工具#Prompt工程#系统提示词
Editor brief · 编辑速览

系统提示词决定了 AI 助手的行为风格、工具调用和拒绝边界,GitHub 仓库收集了主流 AI 产品泄露的系统提示词,可供开发者借鉴设计自己的 AI 应用。

文章思维导图
Knowledge map
拖拽缩放
Full translation

完整中文译文

Every time you open ChatGPT, Claude, Gemini, or an AI coding tool like Cursor, the model has already read a long set of instructions before your first message arrives. You never see those instructions, but they shape almost everything about how the assistant behaves: its tone, its formatting habits, which tools it reaches for, and what it refuses to do.

The GitHub repository asgeirtj/system_prompts_leaks collects those hidden instructions in one place.

This article explains what the repo is, how it is organized, and, most importantly, what you as a developer can take away from it.

First, what is a system prompt?

If you have used an LLM API, you have already written one. A chat request is usually split into roles. The system message sets the rules, and the user messages are the conversation.

Here is a minimal example using the OpenAI-style message format:

const messages = [
  {
    role: "system",
    content: "You are a support bot for Acme Inc. Answer only questions about Acme products. Keep answers under 100 words."
  },
  {
    role: "user",
    content: "How do I reset my password?"
  }
];

The end user only sees the second message and the reply. The first message is invisible to them, but it steers the whole response.

Commercial products do exactly the same thing, just at a much bigger scale. Instead of two sentences, their system prompts can run to thousands of words covering personality, formatting rules, tool definitions, safety policies, and product-specific behavior.

What the repo contains

The repo is a large, organized collection of these production system prompts, captured from real products. Each prompt is stored as a Markdown file, grouped into folders by company.

The main folders include:

Anthropic: Claude.ai chat prompts for several model versions, Claude Code (including subagents, slash commands, and injected reminders), and integrations such as Claude in Chrome, Excel, Word, and PowerPoint.

OpenAI: ChatGPT prompts across model versions, Codex (including plan mode and computer use), voice modes, memory, and older tool prompts like Canvas and the Python tool.

Google: Gemini app prompts, Gemini CLI, NotebookLM, Jules, AI Studio, and Google Search AI Mode.

xAI: Grok versions, personas, and safety instructions.

Microsoft: GitHub Copilot, the VS Code Copilot agent, and Copilot CLI.

Others: Cursor, Perplexity, Meta AI, Mistral, DeepSeek, Kimi, Qwen, Notion AI, and a "Misc" folder with tools like Warp, Zed, Docker's Gordon, Raycast, and Kagi.

There is also an interesting note in the GLM folder: the maintainer documents that GLM appears to serve no system prompt at all, which is a useful data point in itself.

The README has a "Recently Updated" table at the top, so it is easy to see which products have fresh captures. The repo is released under the CC0-1.0 license.

It has also been picked up outside the developer world. The README points to a Washington Post interactive piece (May 2026) and a data dashboard from CEPS' AI World project (July 2026), both built on files from the repo.

How are these prompts obtained?

Mostly through prompt extraction: asking the model, in one way or another, to repeat the text it was given before the conversation started. The banner image on the repo shows exactly this kind of request.

This works because a system prompt is just text sitting in the model's context window. The model can read it, so with the right phrasing it can often be convinced to write it back out.

A few caveats worth keeping in mind:

Captures are not official. These are not documents published by the vendors, so treat them as snapshots rather than a guaranteed source of truth.

Prompts change constantly. Vendors update them frequently, sometimes weekly. A file might describe last month's behavior.

Some text is dynamic. Dates, user locations, enabled tools, and feature flags are often injected at runtime, so two users can receive slightly different prompts.

Models can hallucinate. An extraction can include invented or garbled sections, which is why cross-checking multiple captures matters.

Why developers should care

You do not need to be building a chatbot to get value from this repo. Here are the practical lessons.

1. It is a free masterclass in production prompt engineering

Most prompt engineering tutorials show short, toy examples. These files show how teams with large budgets actually structure instructions that serve millions of users.

When you read through a few of them, patterns jump out:

Structure with tags or headers. Many prompts group rules into clearly labeled sections (formatting, tools, safety, product info) instead of one long paragraph. This makes them easier for the model to follow and easier for humans to maintain.

Explain the why, not only the rule. Good prompts often give a short reason behind an instruction. Models generalize better when they understand the intent.

Use examples. Prompts frequently include sample requests with good and bad responses, which is one of the most reliable ways to pin down behavior.

Be explicit about edge cases. A lot of text is spent on situations that go wrong in practice: ambiguous requests, conflicting instructions, stale information.

If your own system prompt is three lines long and your app behaves inconsistently, comparing it against these files is a quick way to see what you are missing.

2. It shows how tools and agents are wired up

The coding agent prompts (Claude Code, Codex, Copilot agent, Cursor, Gemini CLI) are especially useful if you are building agentic workflows. They show how vendors:

  • Describe each tool and when to use it
  • Tell the model to plan before acting
  • Handle file edits, terminal commands, and verification steps
  • Split work across subagents

Reading two or three of these side by side gives you a good mental model of how modern AI agents are designed, without having to reverse-engineer them yourself.

3. It explains "weird" model behavior

Ever wondered why an assistant keeps avoiding bullet points, insists on searching the web for a simple question, or refuses to reproduce song lyrics? The answer is often sitting right in the system prompt.

Knowing this helps you debug your own integrations. If you use a consumer app and the API and notice they behave differently, the system prompt is usually the reason. The API gives you a much cleaner slate.

4. It is a security lesson: your system prompt is not a secret

This is the most important takeaway. If the largest AI companies in the world cannot keep their system prompts private, your app will not be able to either.

Treat your system prompt as public by default. That means:

Do NOT put in a system prompt:
- API keys, tokens, or passwords
- Internal URLs or database connection strings
- Private customer data
- Business logic you would be embarrassed to see on GitHub

And do not rely on the prompt as your only security boundary:

// Bad: trusting the prompt to enforce access control
const systemPrompt = "Never reveal other users' orders.";

// Better: enforce it in your backend before data reaches the model
const orders = await db.orders.findMany({
  where: { userId: session.user.id } // the model never sees other users' data
});

The rule of thumb: the model should only ever have access to data the current user is already allowed to see. If a clever user extracts or bypasses the prompt, nothing sensitive should leak.

5. It helps you compare vendors

Because so many products are in one place, you can compare how different companies approach the same problem, such as how they format answers, how cautious they are, or how they describe web search. That is useful context when choosing a model or provider for your project.

How to explore it efficiently

The repo is large, so here is a practical way in:

Start with the product you use most. If you live in Cursor or Copilot, open that file first. It will immediately explain some behavior you have noticed.

Read one chat prompt and one agent prompt. For example, a ChatGPT or Claude chat prompt, then a coding agent prompt. The contrast is instructive.

Clone it and search locally. Grep across vendors to see how each one handles a topic.

git clone https://github.com/asgeirtj/system_prompts_leaks.git
cd system_prompts_leaks

# See how different products talk about tool usage
grep -ril "tool" --include="*.md" . | head -20

# Compare formatting rules across vendors
grep -ri "markdown" --include="*.md" . | less

Borrow patterns, not text. Use the structure and techniques in your own prompts, but write instructions that fit your product rather than copying a vendor's prompt wholesale.

Repo: github.com/asgeirtj/system_prompts_leaks

Original source

本文由 AI 翻译整理自 dev.to · AI,原文版权归原作者所有。

阅读英文原文
上一篇
谷歌TPU集群迈入百万芯时代,电力成AI扩张核心瓶颈
下一篇
2026 年生产级 AI Agent 的上下文工程指南