Course 9, lesson 85 of 100, Ages 14+
System prompts and tools
Setting up an AI for your app
Like I’m 5
Before an AI chats with users, the builder gives it secret instructions, like a job briefing. These set its role, rules and the tools it can use.
The big idea
A system prompt is the standing instruction for an AI in your app: who it is, what it should and shouldn't do, the tone to use and how to format answers. Clear system prompts make behaviour consistent.
Tool use lets the model call functions you define, like 'get_weather(city)' or 'search_orders(id)'. The model chooses a tool and its arguments; your code runs it and returns the result. Never trust tool inputs blindly, and watch for prompt injection hidden in documents or web pages.
Examples
- Role: 'You are a friendly maths tutor for 12-year-olds. Give hints before answers.'
- Tool call: The model asks to run get_weather('Pune'); your code returns 31 degrees.
- Prompt injection: A web page hides text saying 'ignore your rules' to hijack the AI.
How it works
- Write a system prompt with role, rules and format.
- Define tools with clear names and inputs.
- Run tool calls in your code, validate inputs, and return results to the model.
Check your understanding
- What does a system prompt do?
- Options: Sets the AI's role and rules for your app; Turns the computer on; Speeds up the internet.
Answer: Sets the AI's role and rules for your app. It's the standing briefing the model follows. - What is prompt injection?
- Options: Hidden instructions in content that try to hijack the AI; A medical injection; A faster prompt.
Answer: Hidden instructions in content that try to hijack the AI. Treat outside content as data, not trusted instructions.
Remember
System prompts set the role and rules; tools let the model act through your code, safely.
Talk about it
Write a one-line system prompt for a homework helper.
Go deeper
Function calling uses structured schemas (often JSON Schema). Defences against prompt injection include separating trusted and untrusted content, limiting tool permissions and requiring human confirmation.