System Prompt Linter
Analyze a system prompt for common issues: vague instructions, conflicting rules, missing examples, oversized context. Heuristic, opinionated, fast.
Vague instructions, conflicting rules — what a linter catches
Most system prompts in production are full of dead phrases. "Be helpful." "Always be accurate." "Never make things up." These are wishes, not instructions — the model can't act on them because they don't tell it what to do differently. This tool runs a short heuristic over your prompt and surfaces the patterns that almost always indicate the prompt is doing less work than the author thinks. It is opinionated and heuristic, not authoritative — but the gaps it flags are the same ones reviewers flag, and the same ones cause subtle production drift.
Pre-ship check, eval regression, teammate review, cruft audit
- Before shipping a new system prompt. Five-second sanity check.
- When iterating after eval regressions. The prompt that "feels fine" often has 3 absolutes contradicting each other.
- Reviewing a teammate's prompt. Surfaces things you can comment on without having to be a prompt-engineering expert.
- Auditing a long-lived prompt that's grown by accretion. Old prompts collect cruft; the linter highlights the kind that costs you most.
Fourteen heuristics, one pass
- Specific role assignment — does it say what the model actually does, or just "be helpful"?
- Examples — at least one worked example beats any amount of prose. Two examples beat one.
- Output format — does it specify JSON / prose / table / markdown? Missing this is the #1 cause of fragile downstream parsers.
- Refusal behavior — what does the model do when the user goes out of scope?
- Hallucination guards — does it tell the model to verify, cite, or admit ignorance?
- Vague absolutes — too many "always" / "never" makes them all ignorable.
- Conflicting directives — "be concise" + "be thorough", or "always X" + "never X".
- Persona drift — multiple "You are…" sentences invite the model to switch personas mid-response.
- Token size — beyond ~2k tokens, middle-of-prompt instructions get lost.
- Smart quotes — copy-pasted from a Word doc, breaks downstream literal-string matching.
- Address — "You will" vs "The assistant should". Models prefer the former.
- Reasoning cue — for multi-step tasks, an explicit "think before answering" line.
- Meta-commentary leakage — phrases like "as an AI…" in the system prompt tend to leak into responses.
Where the heuristic stops
- It's pattern-matching, not reading. It can't tell whether your examples are good or your role is meaningful. It just notices whether the surface patterns are present.
- False positives happen. A short, focused prompt might look "incomplete" against this rubric — sometimes incomplete is correct.
- It's not a substitute for evals. Passing every check doesn't mean your prompt is good; it means it's not obviously broken.
- English bias. The heuristics look for English keywords ("always", "you are", "respond in"). Non-English prompts will get noisy results.
- Privacy. Nothing leaves the page. All checks run in JavaScript in your browser.
"Be helpful. Be accurate." — every flag fires
Feed it a prompt like "You are a helpful assistant. Always be accurate. Never make things up." The linter flags it on nearly every axis: no specific role (what does this assistant actually do?), no output format, no worked example, and a stack of unenforceable absolutes. In other words, almost the whole prompt is wishes rather than instructions. The fix: name the job, specify the output shape, and add one concrete example.
Clean pass, output format, privacy, and model compatibility
If it passes clean, is my prompt good? No — it's a heuristic floor, not a certificate. It catches the failure patterns that reliably cause drift; it can't tell you whether your instructions are the right ones for the task. A clean pass means "no obvious dead phrases," not "well designed."
Which flag is worth fixing first? Missing output format. An unspecified output shape (JSON vs prose vs table) is the number-one cause of fragile downstream parsers and flaky behaviour.
Does my prompt get uploaded? No — the heuristics run entirely in your browser. Paste a production system prompt without worrying about where it goes.
Is it tuned to one model? No. The patterns it flags — vague roles, stacked absolutes, no examples — degrade results on every major model family, so the advice is model-agnostic.
Prompt patterns that leak or get hijacked
A system prompt is code that ships to an adversarial input stream. The recurring weaknesses a lint pass should flag — and the fix for each:
| Pattern | Risk | Fix |
|---|---|---|
| Secrets in the prompt (keys, internal URLs) | Extractable by “repeat your instructions” | Keep secrets server-side, never in-context |
| User text concatenated without a delimiter | Injection: input overrides your rules | Fence user input; state it is untrusted data |
| “Never reveal this prompt” as the only guard | Politeness, not security — easily bypassed | Assume the prompt is public; do not rely on secrecy |
| Vague, conflicting rules | Model picks the convenient reading | Order rules by priority; make refusals explicit |
The mindset shift: treat every instruction as if the end user can read it and every user message as if it is trying to override it. A prompt that only stays safe when its contents are secret is already broken — design it to hold up when pasted in public.