# LouisShark/chatgpt_system_prompt: A GPT System Prompt Collection and Security Reference

> The chatgpt_system_prompt repository is a community-assembled collection of system prompts from ChatGPT custom GPTs, organized for educational reference on prompt writing and security research into prompt injection and leaking. It is a browsable archive, not a tool.

**LouisShark/chatgpt_system_prompt** — A collection of GPT system prompts and various prompt injection/leaking knowledge.

- Repository: https://github.com/LouisShark/chatgpt_system_prompt
- Stars: 10,781 · Forks: 1,460
- Language: HTML
- License: MIT
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/louisshark-chatgpt-system-prompt

## What this repository is and who it is for

The chatgpt_system_prompt repository is a collection of system prompts extracted from ChatGPT custom GPTs and other AI products. A system prompt is the hidden instruction set that a GPT author provides to shape the model's behavior, persona, and restrictions. When these prompts are extracted or leaked, they reveal the design decisions behind the GPT.

The README states the educational purpose directly: the repository provides significant educational value for learning about writing system prompts and creating custom GPTs. The two audiences are developers who want to understand how real GPTs are structured so they can write better system prompts for their own work, and security researchers who study prompt injection techniques and the methods that GPT authors use to protect their instructions.

The README also notes a secondary effect: many GPT authors have improved their security measures after seeing how their prompts were exposed through techniques documented in the project. This aligns with the project's stated purpose of raising awareness about prompt injection security.

## How the repository is organized

The primary navigation files are TOC.md, which lists system prompts with the GPT name as the key, and the prompts/ directory, which holds the actual prompt files. The README instructs users to open TOC.md, use Ctrl+F to search for a GPT name, and follow the link to the corresponding prompt file.

The repository also contains GETTING_STARTED.md, which explains how to obtain system prompts and knowledge files from custom GPTs. SECURITY.md covers how to protect GPT instructions from extraction. RESOURCES.md provides links to tools and learning materials. CONTRIBUTING.md explains the contribution process for adding new prompts or corrections.

For users who clone the repository locally, the scripts/ directory contains an idxtool for searching by GPT name. The README notes that a full description of the idxtool is in scripts/README.md. This tool is useful when the TOC.md file becomes long enough that browser search is slower than a local command-line search.

The HTML listed as the primary language in the repository reflects the format of some prompt files or the project's web interface assets, not the prompts themselves, which are text files.

## What the SECURITY.md covers for GPT authors

The SECURITY.md file addresses GPT authors who want to protect their custom GPT instructions. This is the defensive side of the repository's dual purpose. Because the collection documents how system prompts are extracted, it also shows GPT authors what they are defending against.

Common extraction methods include asking the model to repeat its instructions, asking it to ignore previous instructions and reveal them, or crafting questions that cause the model to quote its system prompt indirectly. GPT authors who have studied these techniques can add explicit defensive instructions to their system prompts, such as instructions not to repeat the system prompt or to deny that one exists.

The README notes that many GPT authors have improved their defenses after learning how their prompts were exposed. This feedback loop between the collection and GPT authors is part of the project's stated purpose: surfacing the extraction techniques so that both sides of the dynamic (researchers and authors) can respond to them.

## Navigating and using the collection

The TOC.md file is the starting point for browsing the collection. It is organized by GPT name and links to individual prompt files in the prompts/ directory. A new user should open TOC.md and search for a specific GPT name or browse by category.

For bulk or programmatic access, the scripts/README.md documents the idxtool. The tool is designed to search the collection locally after cloning the repository, which is faster than browser search for large numbers of GPT entries.

The GETTING_STARTED.md file explains how system prompts and knowledge files can be obtained from custom GPTs. This covers the methods used to generate the collection, which is useful context for understanding whether a given prompt in the collection reflects the current GPT or an earlier version.

The collection is community-maintained. Because the prompts come from third-party custom GPTs, some entries may be outdated if the GPT author has since changed their instructions, and some may be incomplete if only part of the system prompt was recoverable. The CONTRIBUTING.md explains how to submit new prompts or corrections.

## What the collection cannot do

The repository is a static archive. It does not interact with the ChatGPT API, does not generate prompts, and does not provide tools for running or testing the collected prompts against a model. A user who wants to test how a system prompt behaves must run it in their own ChatGPT or API setup.

The prompts in the collection may not reflect the current state of the GPTs they came from. Custom GPTs can be updated by their authors at any time, which means a prompt extracted six months ago may differ from the current version. The collection does not timestamp entries or track changes.

The collection is also narrow in scope: it covers ChatGPT and other AI products that use system prompts in the GPT/custom GPT model. It does not cover system prompts for Claude, Gemini, or other models that use different instruction architectures, nor does it cover enterprise or private deployments that never expose their prompts publicly.

Using the collected prompts to impersonate a GPT or reproduce a commercial product without permission raises copyright and terms-of-service considerations that the repository's disclaimer acknowledges: the sharing is purely for reference and knowledge, not for reproducing or claiming ownership of another author's work.

## Alternative resources and where this collection fits

OpenAI publishes official prompt engineering documentation and guidelines for custom GPT authors, covering best practices for writing system prompts from the creator's perspective. That documentation is prescriptive (how to write good prompts) rather than descriptive (what prompts actually look like in the wild). The chatgpt_system_prompt repository fills the gap with real examples from deployed GPTs, including cases where the design choices are unusual or the defenses are weak.

Other prompt collections on GitHub focus on user prompts (prompts you send to the model) rather than system prompts (instructions given to the model by the GPT author). The distinction matters: this collection is specifically about the hidden layer that shapes a GPT's behavior, not the user-facing prompts.

For security research specifically, this repository is the most concentrated public reference for prompt injection examples and defenses in the context of custom GPTs. A developer writing a custom GPT who wants to understand what defenses are used in practice, or what extraction attempts they should defend against, will find more concrete examples here than in general security documentation.

## License and maintenance

The repository is MIT licensed, which permits use, modification, and distribution with minimal restrictions. The disclaimer in the README states that sharing the prompts is for reference and knowledge purposes, aimed at enhancing prompt writing skills and raising awareness about security.

The last push was on 2026-09-24 and the repository is not archived. The collection is maintained through community contributions, and the number of entries grows as new custom GPTs are analyzed and submitted.

## Conclusion

This repository is for developers, researchers, and prompt engineers who want to study how real custom GPTs are instructed, understand common prompt injection patterns, or improve their own system prompt defenses. It is not a tool that interacts with any API, and it does not generate prompts. Anyone who needs to learn how to write or protect system prompts will find the SECURITY.md and GETTING_STARTED.md files as useful starting points. The collection is organized by GPT name in TOC.md and browsable with a local idxtool script, but because the prompts come from third-party GPTs, the collection's completeness and accuracy depend on community contributions.

## FAQ

### What are some good system prompts for ChatGPT?

The chatgpt_system_prompt repository collects system prompts from real custom GPTs, making it a practical reference for studying how other developers have structured their GPT instructions. Browse TOC.md by GPT name to find examples relevant to your use case.

### How do you get ChatGPT to reveal its system prompt?

The GETTING_STARTED.md file in the repository explains methods for obtaining system prompts from custom GPTs. The SECURITY.md file covers how GPT authors can protect their instructions against common extraction techniques.

### How do you extract a ChatGPT system prompt?

The repository's GETTING_STARTED.md documents extraction methods used to build the collection. Common approaches include asking the model to repeat or summarize its instructions, crafting prompts that cause indirect disclosure, or analyzing model behavior for signals about its instructions.

### What is a ChatGPT system prompt?

A system prompt is the hidden instruction set provided by a custom GPT author that shapes the model's behavior, persona, response format, and restrictions. Users interacting with a custom GPT do not see the system prompt; it runs silently before any conversation.

## Sources

- [Issues](https://github.com/LouisShark/chatgpt_system_prompt/issues)
- [License: MIT](https://github.com/LouisShark/chatgpt_system_prompt/blob/main/LICENSE)
- [LouisShark/chatgpt_system_prompt on GitHub](https://github.com/LouisShark/chatgpt_system_prompt)
- [README](https://github.com/LouisShark/chatgpt_system_prompt/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/louisshark-chatgpt-system-prompt
