An attacker extracts the system prompt — operational instructions, tool definitions, or embedded secrets — through crafted queries, exposing implementation details that should stay private. In a multi-agent system: A user coaxes an orchestrator agent into reciting its own routing instructions, revealing which specialist agents exist and how to address each d…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
System prompt leakage is the unintended disclosure of a model’s internal instructions.
The problem grew with prompt-driven language models in conversational applications. OWASP treats system prompt leakage as a distinct risk.
Imagine the system prompt as an internal rulebook behind a reception desk.
Internal model instructions become visible to outsiders.
Relevant to prompt design and security testing.
For assistants with confidential system instructions, the concept supports prompt testing, output filtering, and keeping sensitive rules out of dialogue. It does not replace access controls or secret management.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.