Claude system prompts become easier to track in Git

Simon Willison describes a Git-based way to explore Anthropic’s published Claude system prompts. The approach breaks the Markdown source into separate files and timestamped commits so researchers can use standard Git tools to track changes over time.

Claude system prompts become easier to track in Git

Simon Willison has published a simple but useful way to turn Anthropic’s public Claude system prompts into a Git history that can be inspected like code. Instead of treating the prompts as static text on a web page, the method breaks the Markdown source into separate files and records timestamped commits, so changes can be tracked over time with standard Git tools.

The idea builds on a broader point Willison has made before: system prompts are not just implementation details, they are part of the behavior of an AI system. For Claude, Anthropic publishes a set of prompt documents that help shape how the model responds, what it refuses, and how it is supposed to behave in different contexts. Those prompts are long, structured, and updated over time, which makes them hard to inspect by eye once they start changing.

⚡ New to this?

This is about taking the written instructions that guide an AI model, called a system prompt, and putting them into Git, the software many developers use to track changes in code. A Git timeline shows who changed what and when, which makes it easier to compare versions and spot small edits that could affect model behavior.

For non-experts, the important part is that AI systems do not just “learn” from data, they are also steered by instructions that can change over time. If those instructions shift, the model’s behavior can shift too, so having a clear history helps people understand and review what changed.

🦞 OpenClaw angle

For AI automation builders and security teams, this is a useful pattern for auditing prompt drift and spotting behavior changes in model updates. Git-based prompt tracking also gives self-hosters a model for versioning system prompts, policies, and agent instructions in a way that is easy to review and compare.

Git provides a familiar answer to that problem. By splitting the source into files, rather than keeping everything in one large document, each section can be compared individually. Researchers can then use normal Git commands to see what changed, when it changed, and how one version differs from another.

That matters because prompt changes can be subtle. A small wording update, a reordered instruction, or a changed exception can affect how a model answers user requests. If the only copy you have is the latest published version, you lose the history that shows whether a behavior shift came from a deliberate policy change, a safety tweak, or simple editorial cleanup.

Willison’s approach also fits a wider trend in AI security and model auditing. As more organizations deploy LLMs, they need a way to keep track of the instructions that sit above the model, including system prompts, agent rules, and tool-use policies. These instructions are often revised frequently, and without version control they can become difficult to review or explain after the fact.

Anthropic’s published Claude prompts are especially useful for this kind of inspection because they are public, which lets outside researchers study them without reverse engineering the model itself. That makes them a rare source of evidence for how a major frontier model is instructed to behave in practice, including how it handles refusal patterns, tool use, and other policy constraints.

A Git-based timeline also makes comparison easier across different releases. Instead of manually diffing large chunks of text in a browser, a reviewer can check commit history, isolate a specific section, and inspect exactly how the wording evolved. That is the same basic workflow software teams use for code, applied here to the behavioral rules of an AI assistant.

The method does not change Anthropic’s prompts, and it does not expose private internals. What it does is make the published material easier to study in a disciplined way, with a record of how the text has changed as Anthropic updates its Claude documentation and prompt source over time.

Source: Simon Willison ↗

More from Security News