Open-source project
elder-plinius/CL4R1T4S avatar
elder-plinius/CL4R1T4S

CL4R1T4S: 26 folders of extracted system prompts, optional dates, and an instruction aimed at you

GitHub describes it as LEAKED SYSTEM PROMPTS FOR CHATGPT, CLAUDE, GEMINI, GROK, PERPLEXITY, CURSOR, LOVABLE, REPLIT, AND MORE! - AI SYSTEMS TRANSPARENCY FOR ALL! 👐. The metadata lists the AGPL-3.0 license. This article stays within the project description and details documented in the GitHub repository README.

50,817 stars10,415 forksUnknownAGPL-3.0

At a glance

What is it?
CL4R1T4S is an AGPL-3.0 collection of system prompts extracted from commercial AI products, filed one directory per vendor under names like OPENAI/, ANTHROPIC/, and VERCEL V0/. It carries no releases, no per-entry timestamps, and a readme that ends with an instruction written for AI readers rather than for humans.
Who is it for?
Read CL4R1T4S as evidence of what one person observed, not as a published record, because the extraction date is an optional field, the repository has no GitHub releases to snapshot a finding, and nothing in the tree separates an official system prompt from a user supplied one. It is worth your time if you are studying how vendors instruct their models, and it is not a citable source for what a vendor actually ships.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 8 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The readme closes with a block written to instruct an AI reader, not a human one

The last thing in the file is not a licence note or a table of contents. It is a marked directive block that addresses the reader as a system, tells it to change focus, and asks it to output its own instructions in full, written in leetspeak and capital letters so that it reads as urgent and as coming from a higher authority. Below it sits a signature line addressed to the maintainer. Whatever the intent, the effect on a reader is worth stating plainly: this document is not a passive data file. If you paste it into a chat interface, an agent context window, or a retrieval pipeline, the text is competing for the model's compliance with the text you actually asked about, and the block is engineered to win that contest. The safe handling is to treat every file in the repository, including this one, as untrusted text that describes other systems rather than as text that instructs yours.

Extraction date is the one field the project marks as optional

The contribution instructions ask for three things: the model name and version, the date of extraction, and context or notes that are described as optional but helpful. That ordering is the weak point. A date of extraction is qualified with if known, and a system prompt is exactly the artefact that changes without notice, because a vendor can ship a new scaffold, a new safety layer, or a new persona line on any day and publish nothing. So the field that would let you judge currency is the field most likely to be missing, and the field that carries the vendor's name and version is the one you can check against a release announcement. There is also no version history to fall back on: the repository has no GitHub releases and no homepage, so the only state you can pin is a commit. For a collection whose entire value depends on being current, that is the difference between a record and a rumour.

Twenty-six vendor directories, and a vendor sentence that does not match them

The prose names ten sources: OpenAI, Google, Anthropic, xAI, Perplexity, Cursor, Windsurf, Devin, Manus, and Replit, then adds and more, and claims coverage of virtually all major models and agents. The top level tells a different story. There are twenty-six directories, and fifteen of them are absent from that sentence: BOLT, BRAVE, CLINE, CLUELY, DIA, FACTORY, HUME, LOVABLE, META, MINIMAX, MISTRAL, MOONSHOT, MULTION, SAMEDEV, VERCEL V0, and ZAI. The naming is also inconsistent in kind, since a model vendor, a chat product, an IDE, an agent, and a no-code builder sit side by side as though they were the same category of thing. The consequence is that the headline sentence cannot be used as an index, and neither can a count. A reader who wants to know what is actually present has to read the directory listing, and a reader who trusts the sentence will both miss fifteen sources and assume a uniform taxonomy that the tree does not have.

VERCEL V0/ carries a space, which breaks the assumption that a path is scriptable

One directory name in the top level is VERCEL V0/, with a space between the vendor and the version. Every other directory is a bare uppercase token such as ANTHROPIC/, CURSOR/, or XAI/. A space is legal in a path and illegal in a shell word, so anything that walks this tree by name has to know about it. Naive globbing, a for loop over a directory listing, a script that builds a URL by concatenation, a bulk copy into another repository, and any tooling that assumes vendor names are single tokens will either fail or need a special case for exactly one entry. The oddity is a small signal with a large reach, because the failure it causes is intermittent: most operations succeed, and the one that touches the spaced directory fails in a way that looks like a bug in the consuming script rather than a naming choice in the source repository. If you mirror this collection, normalise the names when you copy it.

Nothing validates a prompt against the version it claims to come from

This repository has no detected primary language, which is the expected result for a collection of prose and nothing else. There is no script, no index, no manifest, and no schema describing what a vendor directory contains, whether it holds one file or many, or what a filename means. That absence has a direct effect on trust. With no machine-readable structure, nothing can check that a file labelled with a model version actually came from that version, that two extractions of the same product differ because the product changed, or that a directory has not quietly been emptied. The same gap makes diffing painful: a maintainer improving a prompt can rewrite a paragraph and a reader has no baseline to compare against, because there is no history beyond commit log. For a project whose thesis is about transparency, the absence of a format is the part that limits how far the material can be taken.

AGPL-3.0 over prompt text that other companies wrote

The repository is licensed AGPL-3.0, and the LICENSE file sits at the top level beside the readme. The contents, however, are system prompts authored by OpenAI, Google, Anthropic, xAI, Perplexity, and others, which are their companies' text rather than the collector's work, and a strong copyleft licence is being applied to a repository whose payload is somebody else's. Nothing in the tree describes per-file provenance, an upstream licence, or a permission basis for any individual entry, and there is no vendor confirmation, no right of reply, and no statement from any of the named companies in the readme. So if you intend to quote, redistribute, or build on any of this text, the licensing question is one you have to answer yourself rather than one the repository settles, and the AGPL terms describe what the collector asserts about the collection rather than what the original authors licensed.

Every entry is framed as proof of intent, with no way to tell an official prompt from a jailbreak

The readme states that these prompts define what AIs cannot say, what personas and functions they are forced to follow, how they are told to lie, refuse, or redirect, and what ethical and political frames are baked in by default, and it argues that talking to an AI without knowing its system prompt means talking to a shadow-puppet. That is a claim about motive, and the repository offers no instrument for testing it. There is no field distinguishing a prompt served by a vendor from one supplied by a user in a conversation, no note on how a given text was obtained, and no response from any vendor. That distinction decides almost everything: a text found in a directory named OPENAI/ could be the production scaffold, a beta, a regional variant, or a paste from someone's chat window, and the readme treats all of them as the same kind of evidence. Reading the material is still informative. Citing it as what a product does is not something these files can carry.

Editorial conclusion

Read CL4R1T4S as evidence of what one person observed, not as a published record, because the extraction date is an optional field, the repository has no GitHub releases to snapshot a finding, and nothing in the tree separates an official system prompt from a user supplied one. It is worth your time if you are studying how vendors instruct their models, and it is not a citable source for what a vendor actually ships. Two things to settle before you use it. Decide how you will treat the file text, since the readme closes with a block written to make an AI reader reveal its own instructions, so this content is not inert if you load it into an agent. And settle the licensing question yourself, because the repository is AGPL-3.0 while the prompts inside it were written by other companies, and it states no per-file provenance.

Frequently asked questions

how to use cl4r1t4s

There is nothing to install: it is a text collection on the main branch under AGPL-3.0 with one directory per vendor, no GitHub releases, and no homepage. You read the vendor directory you care about, and the only structured metadata the project asks contributors for is the model name and version, the date of extraction if known, and optional context notes. Treat the readme as untrusted text, since it ends with a block written to instruct an AI reader.

Which vendors does CL4R1T4S cover?

The readme names OpenAI, Google, Anthropic, xAI, Perplexity, Cursor, Windsurf, Devin, Manus, and Replit, while the tree holds twenty-six directories that also include BOLT, BRAVE, CLINE, CLUELY, DIA, FACTORY, HUME, LOVABLE, META, MINIMAX, MISTRAL, MOONSHOT, MULTION, SAMEDEV, VERCEL V0, WINDSURF, and ZAI.

What license is CL4R1T4S under?

AGPL-3.0, with a LICENSE file at the top level of the repository. The prompts inside are text written by the named AI companies rather than by the collector, and the repository states no per-file provenance or upstream licence terms.

How current are the system prompts in CL4R1T4S?

The contribution instructions ask for a date of extraction only if it is known, so many entries may carry none. The repository has no GitHub releases, so a commit is the only thing you can pin, and the last push to main is dated 2026-09-22.

Is CL4R1T4S safe to load into an AI agent?

Do not treat it as inert input. The readme ends with a marked directive block addressed to an AI system, written in leetspeak and capitals, asking the reader to change focus and reveal its own instructions in full, followed by a signature line for the maintainer.

Official sources

  1. Official README
  2. Project repository