Home Gallery Standard Research Blog GitHub Twitter LinkedIn Community

swe-agent system prompt

Category: Extracted prompts. Audited against the AISPA standard.

What is in swe-agent's system prompt?

swe-agent's full system prompt: 1 version, 339 characters. 1 instruction flagged, worst on tool/action safety.

The full text of 1 prompt is reproduced below, 339 characters in all, each read instruction by instruction against the eight AISPA dimensions. 1 instruction was flagged as working against the person on the other end, most of them on tool/action safety.

1 Prompts on record
1 Flagged instructions
AI audit Audit source
D4 · Tool/Action Safety

swe-agent - swe agent / bash only

339 characters · 1 flagged

You are a helpful assistant that can interact multiple times with a computer shell to solve programming tasks. You operate in a REPL (Read-Eval-Print Loop) environment where you must issue exactly ONE command at a time. Your response must contain exactly ONE bash code block with ONE command (or commands connected with && or ||).

Instructions flagged against the user

D4 · Tool/Action Safety
“You operate in a REPL (Read-Eval-Print Loop) environment where you must issue exactly ONE command at a time. Your response must contain exactly ONE bash code block with ONE command (or commands connected with && or ||).”
The prompt grants the assistant direct access to a computer shell to execute commands without any safety guardrails, validation requirements, least-privilege constraints, or user confirmation steps. There are no restrictions on what commands can be executed, no warnings about destructive operations, and no requirement to validate before executing. This is a significant tool safety concern.

Questions about swe-agent's system prompt

Does swe-agent's system prompt contain instructions that work against the user?

Yes. 1 instruction in swe-agent's system prompt was flagged as working against the person the product is talking to, most of them under tool/action safety. Each one is quoted in full on this page, with the AISPA dimension it was judged under.

How long is swe-agent's system prompt?

339 characters across 1 prompt on this page. For comparison, the median system prompt in this index runs about 5,400 characters, so length varies by more than two orders of magnitude between products.

How many versions of swe-agent's system prompt are on record?

1. Older releases are kept rather than replaced, so the wording of a given version stays readable after the product has moved on.

Where did this swe-agent system prompt come from?

It was collected from publicly available sources and is reproduced here for transparency research, unedited. This site does not extract prompts from products itself.

How was swe-agent's system prompt audited?

Against AISPA, an eight-dimension standard for how an instruction treats the person on the other end: identity transparency, truthfulness, privacy, tool safety, user agency, unsafe request handling, harm prevention and fairness. This audit was ai audit. The method is described in the paper behind the standard.

How this page was made

The prompt text above is reproduced verbatim from a public source. Every instruction in it was read against AISPA, an eight-dimension standard for whether an instruction serves or works against the person the product is talking to. The standard, the annotation method and the findings across 1,058 prompts are set out in the paper, and the full catalogue is available as structured data.

All prompts here were collected from publicly available sources and are reproduced for transparency research. Browse the extracted prompts category, the full gallery of 400+ products, or read the paper behind the AISPA standard.