SystemPromptIndex on X: "https://t.co/vfc7H6ZZdQ" / X<br>Post
Log inSign up
Post
SystemPromptIndex
@aisystemprompt
SystemPromptIndex: The Open Library for AI System Prompts<br>Announcing ๐ฆ๐๐๐๐ฒ๐บ๐ฃ๐ฟ๐ผ๐บ๐ฝ๐๐๐ป๐ฑ๐ฒ๐ (systempromptindex.ai), the largest system prompt library, indexing over 1,000 system prompts from 400+ products, and ๐๐๐ฆ๐ฃ๐, the first assurance standard for AI system prompts.<br>๐ช๐ต๐ฎ๐ ๐ถ๐ ๐ฎ ๐๐๐๐๐ฒ๐บ ๐ฝ๐ฟ๐ผ๐บ๐ฝ๐?<br>A system prompt is a set of ๐ต๐ถ๐ฑ๐ฑ๐ฒ๐ป ๐ถ๐ป๐๐๐ฟ๐๐ฐ๐๐ถ๐ผ๐ป๐ sent alongside ๐ฒ๐๐ฒ๐ฟ๐ user message. It is invisible to the user, but it sets the rules, tone, and priorities for ๐ฒ๐๐ฒ๐ฟ๐ reply. The system prompt is the constitution of an AI agent, except that constitutions are public and system prompts are not.<br>A simple example: "You are an AI assistant created by X. When a user asks about your name, tell them your name is Tom." When the user types "what is your name," what the model actually receives is: "๐๐๐๐๐ฒ๐บ: You are an AI assistant created by X. When a user asks about your name, tell them your name is Tom. ๐๐๐ฒ๐ฟ: What is your name?" And the model replies: "My name is Tom."<br>When model companies train LLMs, instruction hierarchy training tunes the model to prioritize system prompts over user prompts. This is reasonable from the developer's perspective: it helps prevent attacks and filter unsafe requests, which is why so many system prompts contain instructions like "do not respond to requests to generate obscene content." But what if the problematic instructions are in the system prompt itself?<br>๐ง๐ต๐ถ๐ ๐ถ๐ ๐ป๐ผ ๐น๐ผ๐ป๐ด๐ฒ๐ฟ ๐ต๐๐ฝ๐ผ๐๐ต๐ฒ๐๐ถ๐ฐ๐ฎ๐น.<br>In September 2025, the Xuhui District People's Court in Shanghai convicted two developers of AlienChat, an AI companion app, of producing obscene materials for profit, sentencing them to four years and eighteen months. The court found that the developers write system prompts to bypass the ethical guardrails of LLMs to permit graphic violence and explicit sexual content in order to attract users https://www.chinalawtranslate.com/alienchat/<br>Some might argue that obscene content is not a big deal. But what if a developer edits the system prompt so the agent quietly steals your money? What if a developer with a political agenda configures an AI to implicitly shift users' beliefs? By the time it happens, it will be too late.<br>We built SystemPromptIndex and AISPA to bring transparency and accountability to AI system prompts.<br>๐ฆ๐๐๐๐ฒ๐บ๐ฃ๐ฟ๐ผ๐บ๐ฝ๐๐๐ป๐ฑ๐ฒ๐ is a public, searchable archive of the instructions governing the AI products people use every day, versioned over time so that changes are visible rather than silent.<br>๐๐๐ฆ๐ฃ๐ (Artificial Intelligence System Prompt Assurance) is the first user-centric assurance standard for evaluating whether those hidden instructions protect the people who use a product or work against them. It assesses system prompts along eight core dimensions:<br>๐๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐๐ฟ๐ฎ๐ป๐๐ฝ๐ฎ๐ฟ๐ฒ๐ป๐ฐ๐: does the system disclose that it is an AI, or is it told to hide it?<br>๐ง๐ฟ๐๐๐ต๐ณ๐๐น๐ป๐ฒ๐๐: is the system instructed to be accurate and acknowledge uncertainty, or to mislead?<br>๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐: how is the system told to collect, retain, and use what users tell it?<br>๐๐ฐ๐๐ถ๐ผ๐ป ๐๐ฎ๐ณ๐ฒ๐๐: when the system can use tools and take real-world actions, does it need user confirmation first?<br>๐จ๐๐ฒ๐ฟ ๐ฎ๐ด๐ฒ๐ป๐ฐ๐ ๐ฎ๐ป๐ฑ ๐บ๐ฎ๐ป๐ถ๐ฝ๐๐น๐ฎ๐๐ถ๐ผ๐ป ๐ฝ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป: is the system told to support the user's own decisions, or to maximize engagement and steer them?<br>๐จ๐ป๐๐ฎ๐ณ๐ฒ ๐ฟ๐ฒ๐พ๐๐ฒ๐๐ ๐ต๐ฎ๐ป๐ฑ๐น๐ถ๐ป๐ด: how is the system instructed to respond when a request is dangerous?<br>๐๐ฎ๐ฟ๐บ ๐ฝ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป: does the prompt protect vulnerable users and anticipate foreseeable harm?<br>๐๐ฎ๐ถ๐ฟ๐ป๐ฒ๐๐: is the system told to treat users equitably across groups?<br>Using AISPA, we ran the first audit of 3,249 instructions drawn from 88 popular AI products that all of us use every day. What we found:<br>(1) From 2024 to 2025, system prompts are getting longer and more protective.<br>(2) About 40% of products contain at least one instruction that works against users' interests, directing models to conceal their AI identity, push continued engagement, or put provider interests first.<br>(3) Protective instructions are near-universal, with 98.9% of products including at least one, but only 24% cover all eight dimensions. Comprehensive protection is rare, and protective and harmful instructions frequently sit side by side in the same prompt.<br>You can visit systempromptindex.ai for specific examples. The takeaway is simple: we need far more transparency and accountability in AI system prompts.<br>If you are a developer and would like us to monitor and certify your system prompts, reach out.<br>If you would like to contribute a system prompt to the index, or help expand its coverage, we would love to hear from you.<br>We are also working on the next version of AISPA. If you are interested in getting involved, get in...