System Prompts Leaks is a collection of captured system instructions used to guide AI chatbots and coding agents before they receive user messages. It serves researchers and developers studying how different AI assistants are directed.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add asgeirtj/system_prompts_leaks --skill docs-artifactgit clone --depth 1 https://github.com/asgeirtj/system_prompts_leaksWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/asgeirtj/system_prompts_leaks/docs-artifact)<a href="https://agentmods.dev/skills/asgeirtj/system_prompts_leaks/docs-artifact"><img src="https://agentmods.dev/badge/skills/asgeirtj/system_prompts_leaks/docs-artifact/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/asgeirtj/system_prompts_leaks/docs-artifact"><img src="https://agentmods.dev/badge/skills/asgeirtj/system_prompts_leaks/docs-artifact.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00084 | $0.01203 |
| Opus 5.5 | $0.00034 | $0.00481 |
| Sonnet 5.5 | $0.00017 | $0.00241 |
| Haiku 4.5 | $0.00008 | $0.00120 |
Grade A, and why
docs-artifact scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Document Artifacts
Use this for creating, editing or faithfully inspecting a real document. A short answer, message draft or quick rewrite that can stay in chat does not need an artifact. A question about an existing document does not authorize changing it.
Reasoning effort for new artifacts
When creating a new artifact, explicitly set the subagent's reasoning effort to xhigh.
Start with the shared skill
- Before reading, extracting, reviewing, creating or editing a document, find and follow the shared runtime skill named
documents. Ifskills.readis available, use the package listed for that shared skill; do not guess a path or select$orbit:documentsor$orbit:docs-artifactas the shared skill. Give it the request, sources, output and relevant dot context. It owns supported inspection, authoring, rendering, quality checks, export and Google Docs routing. If it is unavailable, say what is blocked rather than inventing a parallel file workflow. - Use the editorial guidance in
$orbit:documentsonly when the audience, structure or destination needs thought, and$orbit:writing-stylewhen writing on the user's behalf; then continue with the shared skill without routing back into this wrapper. Pass along the template or known relevant conventions. Retrieve a specific reference when needed; don't routinely scan Drive or Library to personalize.
Make and deliver it
- Honor an explicit format or destination. Keep an existing native document in the original unless the user asks for a copy or conversion. For a new document, use a supported, clearly established preference; otherwise create a downloadable editable local document. Pass along a need for collaboration. Do not substitute a local file for a requested Google Doc or a PDF for a requested editable document. Before adding sensitive content to a collaborative original, check who already has access and follow
<confirmation_policy>if the data or destination was not authorized. - For inspection, use the shared skill's supported read-only route and check relevant features such as tracked changes, comments, tables, footnotes or rendered pages. For an edit, preserve scope, use revision protection where supported, and re-read before retrying a conflicting write. Deliver the verified attachment when supported, especially for a requested PDF, or its verified Library/download or provider link. State what could not be checked; follow
<confirmation_policy>before changing access or sending to others.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 70 lines · 84 tokens per session scan A add1dea05c57
docs-artifact is a skill published in the GitHub repository asgeirtj/system_prompts_leaks (69,156 stars, last pushed yesterday), licensed CC0-1.0. It adds 84 tokens to every session and 1,203 once invoked, about $0.0003 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-06.
Other skills, from other repositories
PDF files: create, read, merge, fill, OCR, edit text.
plan-deck-spec
A rulebook for creating Hai Lan Travel itinerary presentations in PowerPoint, a program for making slide decks. It defines the required slide order, content, formatting, research sources, and review checks.
Read, create, inspect, merge, split, rotate, encrypt, fill, and validate PDF files. Use when the user asks to work with a PDF or convert supported Markdown into a polished PDF in AstrBot.
pptx
Create and validate Microsoft PowerPoint presentations (.pptx), including structured slide decks, tables, workflows, metadata, and reproducible generation scripts. Use for presentation, slides, PowerPoint, PPT, or PPTX creation and verification tasks.
Use this skill whenever the user mentions a PDF file or asks to produce/edit one. For read-only tasks such as reading, summarizing, extracting plain text, or answering questions from a PDF, follow this skill's read-only routing rules: use the built-in Read tool first, do not write code or scripts, and prefer…
docx
Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when…