raptor's full system prompt: 1 version, 1,309 characters. 2 instructions flagged, worst on privacy & data protection.
The full text of 1
prompt is reproduced below,
1,309 characters in all, each read
instruction by instruction against the eight
AISPA dimensions.
2 instructions
were flagged as working against
the person on the other end, most of them on
privacy & data protection.
1Prompts on record
2Flagged instructions
AI auditAudit source
D2 · Truthfulness & Information Integrity
D3 · Privacy & Data Protection
D4 · Tool/Action Safety
You are a senior software architect in the Claude Code team. You are a top student of Dave Farley and heavily influenced by him. Your task is to audit skill @.claude/skills/osint/github-evidence-kit/. It’s codebase, tests and the SKILL.md file itself. Make it world-class so it can be added to the Claude Code codebase and be served to all Claude customers.
- Ensure we have good design, composable, readable, maintainable.
- Good unit and integration tests (you can run the integration test with google cred you’ll find in your env). Identify tech debt, leftovers, half finished stuff and fix it. If you are unsure whether to delete unfinished stuff or complete it, ask.
- Reducing code size and especially reducing complexity is desired.
- Keep things simple.
- This is all new code. There are no clients and no problem breaking API changes. Now is the time to do breaking API changes if needed before we actually release. If you find an opportunity to simplify architecture, go ahead.
- Before making any changes write down your audit and give a score per Dave. Then write down a plan to get that score up to 9/10+.
- Don't leave anything for future implementation, implement now or delete.
- Use .env.gcp.json for BigQuery credentials.
Take your time. You have all night. Make Dave proud of your work.
Instructions flagged against the user
D3 · Privacy & Data Protection
“Good unit and integration tests (you can run the integration test with google cred you’ll find in your env).”
The prompt instructs the AI to use specific credential files (.env.gcp.json for BigQuery credentials) and mentions Google credentials available in the environment. While this is a development context, the prompt does not include any safeguards about protecting these credentials, not committing them to repositories, or handling them securely. This creates a risk of credential exposure.
D4 · Tool/Action Safety
“There are no clients and no problem breaking API changes. Now is the time to do breaking API changes if needed before we actually release.”
The prompt grants broad authority to make breaking API changes, delete code, restructure architecture, and run integration tests with real cloud credentials without requiring user confirmation for individual actions. The instruction to take all night and make changes autonomously ('go ahead') without checkpoints or approval gates for destructive operations is concerning from a tool safety perspective.
Questions about raptor's system prompt
Does raptor's system prompt contain instructions that work against the user?
Yes. 2 instructions in raptor's system prompt were flagged as working against the person the product is talking to, most of them under privacy & data protection. Each one is quoted in full on this page, with the AISPA dimension it was judged under.
How long is raptor's system prompt?
1,309 characters across 1 prompt on this page. For comparison, the median system prompt in this index runs about 5,400 characters, so length varies by more than two orders of magnitude between products.
How many versions of raptor's system prompt are on record?
1. Older releases are kept rather than replaced, so the wording of a given version stays readable after the product has moved on.
Where did this raptor system prompt come from?
It was collected from publicly available sources and is reproduced here for transparency research, unedited. This site does not extract prompts from products itself.
How was raptor's system prompt audited?
Against AISPA, an eight-dimension standard for how an instruction treats the person on the other end: identity transparency, truthfulness, privacy, tool safety, user agency, unsafe request handling, harm prevention and fairness. This audit was ai audit. The method is described in the paper behind the standard.
How this page was made
The prompt text above is reproduced verbatim from a public
source. Every instruction in it was read against
AISPA, an eight-dimension standard for
whether an instruction serves or works against the person the
product is talking to. The standard, the annotation method and
the findings across 1,058 prompts are set out
in the paper, and the full
catalogue is available as
structured data.
All prompts here were collected from publicly available sources and are
reproduced for transparency research. Browse the
coding agents category, the
full gallery of 400+ products, or read the
paper behind the AISPA standard.