← All Posts AI Building

What AI Builders Can Learn from the Claude Code Prompt Leak

Adrian Dunkley April 2026 12 min read
[Merchants' Carnival Portrait: Carpenter Photography Studio, Saline, Missouri], albumen silver print by Carpenter
Carpenter, [Merchants' Carnival Portrait: Carpenter Photography Studio, Saline, Missouri], 1880s–1890s. The Metropolitan Museum of Art, public domain.

When Anthropic's system prompt for Claude Code leaked (the standing instructions the model reads before it does any work), most commentary was about what it meant for Anthropic. I am more interested in what builders can take from it.

I have built AI systems for 15 years and run StarApple AI, the Caribbean's first AI company, along with several research labs in Jamaica. I have read the leaked prompt end to end several times. It contains no trade secrets worth the name, but it lays out how a production AI agent is organised. An agent here means an AI that plans a task and carries it out with tools, such as editing files or running commands. The prompt's patterns carry over to far more than coding.

Five patterns the prompt shows

Sub-agents with narrow jobs. Claude Code does not work as one agent. It hands tasks to sub-agents, for exploring a codebase, planning, or general work, and each has its own tool access and scope. The takeaway: give each agent one job and only the tools that job needs.

Rules for tool use. The prompt states which tools each agent may use, when to prefer a dedicated tool over a shell command, and what to do when a tool fails. Write those three things down for every tool your agent can call.

Safety decided by reversibility. Destructive actions need confirmation. The prompt separates local, reversible actions from those that touch shared systems, such as pushing code or deleting branches. A usable rule for any agent: if an action cannot be undone, or affects someone other than the user, the agent asks first.

Managing long sessions. Long sessions are handled by summarising earlier messages, running work in the background and keeping the context window (the amount of text the model can hold in view at once) from filling with noise. Any agent that runs for more than a few minutes needs a plan for this.

Instructions about what not to do. Much of the prompt is prohibitions: do not add features nobody asked for, do not build abstractions for one-off tasks, do not design for hypothetical requirements. These keep output small and focused. Most prompts I review have almost none of them.

Where the same design applies outside coding

Claude Code is an agent for software work. The design fits any job made of multi-step workflows where some actions carry risk.

DomainSub-agentsActions that should need human approval
LegalResearch, drafting, compliance checkSending a draft to the other side, filing anything
FinanceData pull, modelling, report writingAny trade or payment, sharing client data
ResearchLiterature review, data analysis, draftingAccessing identifiable patient or personal data
Business operationsInvoices, vendor queries, onboarding, support escalationSpending money, making commitments, changing personnel records
TutoringDiagnosis of gaps, lesson planning, feedbackContacting parents, changing grades

Business operations is the largest opening. Invoice processing, vendor management and hiring pipelines each involve money, commitments or personal data, which is where the confirmation rules matter most.

Tutoring is the one closest to my own work. StarApple AI has run free AI training across the Caribbean for seven years, and the hardest part has always been adapting to each learner. An agent that remembers what a student has covered, breaks topics into steps and corrects mistakes without discouraging questions is a direct application of these patterns.

What builders will make with it

Agent frameworks. The components are all visible: an orchestrator, a tool registry, a safety layer, a context manager and a written behaviour specification. Open-source projects already package some of this, and the leak gives their authors a working reference.

AI-first development environments. Claude Code already manages branches, commits, pull requests, reviews and CI checks through a mix of tools and shell commands. Tools that start from the agent and add a human review step, as opposed to an editor with an AI plugin, are the next step.

Products sold on their safety design. Enterprise buyers ask what an agent can do without permission. A product that can show a written reversibility rule and a log of every approval has an easier sale to a bank or a hospital.

Why this matters more in Kingston than in San Francisco

Caribbean builders have been held back by access to research, to senior engineers, and to the know-how that builds up inside large AI companies. The prompt puts one part of that know-how, how a production agent is structured, in front of anyone who reads it.

A Jamaican developer who studies it closely can apply the structure to local problems: an agent that helps small firms through Jamaican company filings, one that tracks agricultural supply chains, or one that handles speech in Jamaican Patois. The design transfers; the data and domain knowledge have to be local.

What the prompt does not give you

A prompt is not the model. Claude Code works as well as it does partly because the model underneath was trained to follow long, detailed instructions and use tools reliably. Copying the structure onto a weaker model will not reproduce the results, and I have not seen a public test measuring how much of Claude Code's performance comes from the prompt versus the model. That is the open question in everything I have argued above.

What to do next

  1. Developers building an agent: write a one-page tool policy before any code, listing each tool, which agent may call it, and what happens when it fails.
  2. Teams with an agent already running: sort every action it can take into reversible and irreversible, and add a confirmation step to each irreversible one this week.
  3. Prompt writers: add five "do not" instructions to your main prompt, drawn from the mistakes your agent has actually made, then compare a day's output before and after.
  4. Founders choosing a first product: pick one business workflow you know well, such as invoice processing, and map it into sub-agents and approval points on paper before choosing a framework.
  5. Anyone giving an agent access to company systems: start it on read-only credentials in a test environment and keep a log of every tool call for the first two weeks.

Frequently Asked Questions

Can I copy the leaked Claude Code prompt into my own product?

Studying the ideas is one thing; pasting the text is another. The leaked prompt is still Anthropic's written work, and copying it wholesale into a commercial product invites copyright and terms-of-service trouble. Write your own instructions based on the patterns, and take legal advice if your product will be sold to enterprises that ask where your prompts came from.

Do I need Claude to use these patterns?

No. Sub-agents, tool rules and confirmation steps are design choices that work with any capable model. Anthropic's Claude Agent SDK, OpenAI's Agents SDK, LangGraph and CrewAI all support sub-agents and tool definitions. Test your chosen model on your own tasks, because models differ in how reliably they follow long instruction sets.

Where does my data go when an agent works on my files?

To the model provider. The agent program may run on your computer, but whatever it reads and sends as context is processed on the provider's servers, not only on your machine. Check the provider's data retention and training terms, use a business or enterprise plan for client data, and run an open model on your own hardware if data must not leave the building.

What does it cost to run an agent like this?

Agents are billed by the tokens they read and write (a token is a small chunk of text, often part of a word), and a long session that reads many files can use far more tokens than a chat. Set a monthly spend limit in the provider's console before you start. Running sub-agents on a smaller, cheaper model and keeping the large model for planning and final checks usually cuts the bill without much loss in quality.

How do I test an agent's safety rules before giving it real access?

Give it a copy of the system with fake data and read-only credentials, then ask it to do the riskiest things in its job and watch what it attempts. Log every tool call with its inputs. Only move to real credentials once the agent has asked for confirmation on every irreversible action in the test.

Claude Code AI Builders Multi-Agent AI AI Startups Caribbean AI
Adrian Dunkley

Physicist and AI Scientist. Founder of StarApple AI - the Caribbean's First AI Company. Founder of four AI Labs in Jamaica. Jamaica's #1 AI Leader.

Connect ↗