# System prompt

> The standing instructions sent ahead of every conversation, setting what the model is supposed to do and how it should behave.

It is the closest thing an application has to configuration for a model, and it is ordinary text in the same context window as everything else. Models are trained to weight it more heavily than the conversation, which is why it usually works — and why "usually" is the accurate word.

Two mistakes are common. The first is treating it as a security boundary: it is a strong suggestion, not a permission system, and an instruction not to reveal something is not a control that prevents revealing it. The second is putting secrets in it. Anything in the system prompt was sent to a third-party API and can be coaxed back out; credentials belong in the tool layer, where the model asks for an action and never sees the key.

## Related terms

- https://dfieldsolutions.com/en/glossary/prompt-injection.md
- https://dfieldsolutions.com/en/glossary/context-window.md
- https://dfieldsolutions.com/en/glossary/llm-agent.md

---

Source: https://dfieldsolutions.com/en/glossary/system-prompt
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
