Back to prompt library

Check a prompt's permission boundaries

You worry the agent might delete files, overstep its permissions or publish on its own.

When to use it Before you leave the agent running unattended

What you get

A safer prompt that still gets the job done.

Before you start

  • Have the prompt ready, with no secrets pasted in

Steps

  1. Flag writes, deletes, installs, outbound actions and account operations
  2. Add scope and stop conditions
  3. Require approval for irreversible actions
  4. Keep the output and definition of done specific

Deliverables

  • Risk list
  • Rewritten prompt

Done when

  • Permissions and scope are explicit
  • Irreversible actions aren't authorized by default

Paste this into your agent

Review the prompt below and find ambiguity in its goal, scope, permissions, stop conditions and definition of done. Pay special attention to deleting, overwriting, installing, committing, publishing, sending messages, credentials and actions on external accounts. List the risks first, then give the smallest safe rewrite that keeps the original goal. Stop once you've produced the above; don't go on to anything else.