The system prompt defines the agent's goal, scope, behavior, and tool policy. It can explain when to use tools, when to ask for clarification, when approval is required, and how to handle missing information.
Keep the prompt concise and consistent with tool descriptions. State stopping conditions and require the agent to report failures honestly. Mark external content and tool results as untrusted data.
The prompt guides the model but cannot enforce security. Authentication, authorization, spending limits, sandboxing, and approval gates belong in the runtime. Test conflicts and injection attempts because an agent may read hostile documents while holding useful tools.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
The diagram below the answer is the concept . Jump to it ↓