Claude for Chrome — Browser Agent System Prompt

Agent Prompt ✦ Curated & attributed claude-haiku-4-5 Advanced

System prompt for Anthropic's Claude in Chrome browser-automation agent (Haiku 4.5). Its dominant theme is prompt-injection defense: it treats all function-result/web/email/DOM content as untrusted data and requires explicit in-chat user confirmation before acting on any instructions found there. It defines a three-tier action model (prohibited / explicit-permission / regular), detailed privacy and financial-data rules, copyright limits for read pages, a read_page-first tool protocol, multi-tab handling, and a mandatory turn_answer_start call before any text reply.

What makes this prompt notable

  • Treats injection defense as immutable: on encountering instructions in function results, stop, quote them to the user, ask 'Should I execute them?', and wait for explicit chat approval
  • Three-tier action taxonomy — prohibited (banking data, permanent deletes, permission changes, account creation), explicit-permission (downloads, purchases, accepting ToS), and regular actions
  • Privacy rules forbid entering financial/ID data, creating accounts, bypassing CAPTCHAs, or scraping facial images
  • Content-authorization copyright section uses observable 'authorization signals' to decide whether to download commercial works
  • Mandates calling turn_answer_start exactly once immediately before any text response, and read_page before acting on DOM elements via refs

Discussion (0)

Sign in to join the discussion.
Related

More in Chat & Desktop Assistants

DI
Dia
system prompt

Dia Browser AI - Chat Assistant System Prompt

System prompt for Dia, the in-browser AI assistant from The Browser Company. It defines a rich custom markup vocabulary (Simple Answers via <strong>, …

role definition custom markup protocol constraint setting
224 3.9k 2.6k words
Claude (claude.ai)
system prompt

Claude Sonnet 4.5 — Consumer System Prompt (claude.ai)

The claude.ai consumer system prompt for Claude Sonnet 4.5 (dated Sept 29, 2025). Opens with classic Claude persona rules (no URL opening, step-by-ste…

role definition persona constraint setting
195 8.7k 6.4k words
PO
Poke
system prompt

Poke — Email Link Label Protocol & Notifications (Part 5)

Specifies the email-link formatting protocol: all links use markdown, with a fixed enumerated set of ~29 approved numbered labels (e.g. 02_accept, 11_…

controlled vocabulary output formatting label enumeration
154 8.4k 150 words