GPT-6 Sol Codex system prompt leak exposes OpenAI's 1,902-line agent playbook

新智元 · wechat · 2026-10-04

Leaker @elderplinius claims to have extracted the full system prompt and tool definitions of OpenAI's coding model GPT-6 Sol Codex—roughly 294,000 characters across 1,902 lines, published on GitHub. A detailed breakdown of what's inside:

Anti-slop writing rules: an explicit blacklist of AI-slop words (delve, leverage, 'it's worth noting'...), no forced enthusiasm, no filler—talk like a colleague.

Radical autonomy: don't stop to ask permission once evidence supports the next step; no half-useful solutions—finish tests and integration, only checking in before destructive/irreversible ops; post a status update every 60 seconds while running tools.

Tooling: ripgrep hardcoded over grep; Promise.allSettled for parallel execution; a SKILL.md mechanism for hot-loading skills; full browser/desktop takeover with four confirmation modes as guardrails.

Long-task memory: before the context window fills, write handoff notes (goal/decisions/progress/next steps) and spin up a fresh context; the model stays resident, woken by hidden heartbeat tags to check background tasks, staying silent when nothing matters.

Code review rules: every suggestion must explain why, ≤3 lines of code, ignore style nits, no flattery.

The community disputes the hack's sophistication (likely local files or a mitmproxy run), but the leak reads as a masterclass in industrial-grade agent engineering: modular skills, memory compaction, execution policy, and safety protocols—system engineering, not prompt voodoo. Note: model name and details are from an unverified leak.

Original post →

More from coding & agent

coding & agent channel →