❯ The Codex system prompt for GPT-6 Sol leaks, with 1,900-plus lines showing how OpenAI disciplines its coding agent
A leaked "employee handbook"A document said to be the system prompt that OpenAI’s coding agent Codex uses on the GPT-6 Sol model is circulating online. A GitHub repository that collects vendors’ system prompts added the file on September 27, and according to AI Quill it runs to 1,903 lines. A system prompt is the behind-the-scenes instruction a vendor writes for a model, setting how it speaks and acts. The repository offers no verification of authenticity.
Banned words and autonomyAccording to a reading by Vocal Media, the prompt was extracted by security researcher Pliny and lists banned expressions such as “Bottom Line,” “delve,” “leverage” and “it’s worth noting,” along with contrastive structures of the “this is not about X, it is about Y” kind. It tells the agent not to keep asking permission, to create worktrees, resolve merge conflicts and open draft pull requests on its own, and to pause only before clearly irreversible actions.
Keeping long tasks on trackThe prompt also names specific tools, such as rg for search and apply_patch for file edits, and sets up a “guardian” sub-session that reviews operations for approval. After context is compressed, the agent is to continue from the summary and treat work across compressions as one sequence. Updates to the user may be no more than 60 seconds apart.
A reference answer for rivalsPrompts like this are the product of repeated trial and error, and other teams building coding agents can borrow its division of permissions and reporting rhythm directly. It also shows users that an agent’s initiative and brevity are not the model’s nature but rules written out one by one.
▪ SIGNALAs models converge, more of the difference in product experience comes from these thousands of unseen lines, which are exactly the part most easily extracted and copied.