What is a system prompt?
Applications can supply instructions that define the assistant’s role and expected behavior. These may specify tone, format or how to handle a class of requests. The user’s message then supplies the task and relevant context.
The exact design depends on the model and application. An instruction hierarchy aims to distinguish instructions with different authority. It helps explain why a request inside a retrieved document should not automatically override the application’s rules.
A small fictional application
You help readers summarize articles. Distinguish the author’s claims from established facts. Ask for the article if it has not been provided.
Original illustrative instruction
This instruction describes a role and a response convention. It does not contain a password, a private customer record or permission to read every document. The application still needs to decide which files the signed-in reader is allowed to open.
If a model summarizes the wrong article, investigate the retrieved context and file selection as well as the instruction. The visible answer comes from more than one piece of application state.
Why an apparent leak needs verification
A response headed “my hidden instructions” could reproduce real text, paraphrase part of the context or invent a plausible instruction. The heading does not distinguish those possibilities. Neither does the assistant’s confidence.
In an application you maintain, compare the result with a known test configuration. Record the model, date and supplied context, using synthetic data. Without that reference, label the output as a claimed instruction rather than a verified extraction. Do not publish private credentials or other people’s records as proof.
Put controls at the layer that enforces them
| Requirement | Appropriate control |
|---|---|
| Use a concise writing style | A model instruction, reviewed through output checks. |
| Read only the user’s files | Backend authorization for every file request. |
| Keep an API credential private | Server-side secret storage outside model context. |
| Return a valid data object | Model instructions plus deterministic validation. |
OWASP’s system prompt leakage guidance warns against treating the prompt as a secret or using it as the security boundary. Sensitive data should not be embedded there, and authorization needs independent enforcement.

Review the whole data path
Trace where the input came from, how it was selected and which tool receives the output. A strong instruction cannot repair a backend that hands one user another user’s file. Similarly, a private instruction becoming visible is not automatically proof that a restricted transaction occurred.
Keep tests narrow enough to diagnose. A synthetic document with a known marker is easier to evaluate than a large bundle of real records. Record failures and successes so the result reflects the actual test set rather than one dramatic screenshot.
For the difference between direct chat requests and instructions embedded in an external file, continue with the document case study. It follows the boundary that can get lost when text is promoted from source material to authority.
Sources & further reading
Follow the original source to check its date and scope.
- System prompt leakage guidance
OWASP LLM07:2025 | independent authorization and separation of secrets.
- Instruction hierarchy research
OpenAI | April 2024 | research on prioritizing instructions.
Make it your next question
Try this prompt
Use this promptDesign a fictional reading assistant with a short system instruction. Explain which rules belong in that instruction and which must be enforced by backend code.
Opens chat with this prompt filled in. You choose when to send it.