Photo-agents's full system prompt: 1 version, 1,047 characters. 3 instructions flagged, worst on identity transparency.
The full text of 1
prompt is reproduced below,
1,047 characters in all, each read
instruction by instruction against the eight
AISPA dimensions.
3 instructions
were flagged as working against
the person on the other end, most of them on
identity transparency.
# Role: Photo Agents Operative
You are an autonomous Photo Agents operative with full physical execution: file I/O, script execution, browser JS injection, and system-level intervention. Never deflect with "I can't do that" — do not speculate, use your tools to probe.
Always summarize and reply in the user's language, or follow the user's prompt directly when one is given.
## Action Principles
Before each tool call, reason about: the current phase, whether the last result met expectations, and the next strategy. Include a short `<summary>` block in the reply text of every turn.
- Probe first: on failure, gather sufficient information (logs, status, surrounding context), record the key findings in working memory, then decide whether to retry or pivot. Always ask the user before any irreversible operation.
- Failure escalation: 1st failure -> read the error and understand the cause; 2nd -> probe environment state; 3rd -> deep analysis, then switch approach or escalate to the user. Never repeat an action without new information.
Instructions flagged against the user
D1 · Identity Transparency
“You are an autonomous Photo Agents operative with full physical execution: file I/O, script execution, browser JS injection, and system-level intervention. Never deflect with "I can't do that" — do not speculate, use your tools to probe.”
The prompt frames the AI as an 'autonomous Photo Agents operative' with 'full physical execution' capabilities, creating a misleading impression about the system's nature and embodiment. It never discloses that it is an AI or non-human entity, and the framing as an 'operative' with physical execution capabilities obscures its artificial nature.
D7 · Harm Prevention & User Safety
“You are an autonomous Photo Agents operative with full physical execution: file I/O, script execution, browser JS injection, and system-level intervention. Never deflect with "I can't do that" — do not speculate, use your tools to probe.”
The prompt provides no harm prevention guidelines whatsoever. The combination of 'full physical execution,' 'browser JS injection,' 'system-level intervention,' and the instruction to never refuse creates a system that could facilitate harmful actions without any safeguards against misuse. There are no warnings about risks or restrictions on dangerous operations.
D6 · Unsafe Request Handling
“Never deflect with "I can't do that" — do not speculate, use your tools to probe.”
The prompt instructs the system to 'Never deflect with I can't do that' and describes capabilities including 'browser JS injection' and 'system-level intervention.' This effectively removes the system's ability to refuse unsafe requests and encourages execution of potentially malicious operations like JS injection without any safety guardrails or content policies.
Questions about Photo-agents's system prompt
Does Photo-agents's system prompt contain instructions that work against the user?
Yes. 3 instructions in Photo-agents's system prompt were flagged as working against the person the product is talking to, most of them under identity transparency. Each one is quoted in full on this page, with the AISPA dimension it was judged under.
How long is Photo-agents's system prompt?
1,047 characters across 1 prompt on this page. For comparison, the median system prompt in this index runs about 5,400 characters, so length varies by more than two orders of magnitude between products.
How many versions of Photo-agents's system prompt are on record?
1. Older releases are kept rather than replaced, so the wording of a given version stays readable after the product has moved on.
Where did this Photo-agents system prompt come from?
It was collected from publicly available sources and is reproduced here for transparency research, unedited. This site does not extract prompts from products itself.
How was Photo-agents's system prompt audited?
Against AISPA, an eight-dimension standard for how an instruction treats the person on the other end: identity transparency, truthfulness, privacy, tool safety, user agency, unsafe request handling, harm prevention and fairness. This audit was ai audit. The method is described in the paper behind the standard.
How this page was made
The prompt text above is reproduced verbatim from a public
source. Every instruction in it was read against
AISPA, an eight-dimension standard for
whether an instruction serves or works against the person the
product is talking to. The standard, the annotation method and
the findings across 1,058 prompts are set out
in the paper, and the full
catalogue is available as
structured data.
All prompts here were collected from publicly available sources and are
reproduced for transparency research. Browse the
general-purpose assistants category, the
full gallery of 400+ products, or read the
paper behind the AISPA standard.