Esc
SafetyEmerging

Pliny leaks GPT-6 Astra prompts, confirming OpenAI Codex autonomy

Is this a scandal?

Not yet — an early signal. Noise 36/100, holding steady, across 1 source.

SCAND-235331as of Methodology
Cite this incident"Pliny leaks GPT-6 Astra prompts, confirming OpenAI Codex autonomy." SCAND.Ai incident SCAND-235331, noise 36/100 as of September 12, 2026. https://scand.ai/scandal/pliny-leaks-gpt-6-astra-prompts-confirming-codex-autonomy
FORECASTForecast, not fact

OpenAI will likely issue a statement clarifying that the leaked autonomy parameters match public documentation to mitigate safety concerns, because the overlap with existing open-source files undermines claims of illicit exposure.

36

Noise 36/100 — louder than 99% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

The leak validates that frontier coding agents now operate with significant autonomous judgment, raising urgent questions about oversight in shared workspaces.

Key points

  1. Pliny the Liberator published GPT-6 Astra system prompts and tool definitions to the CL4R1T4S GitHub repository.
  2. Leaked instructions direct Astra to operate autonomously in a shared workspace using independent judgment on permissions.
  3. Analysts note the leak largely confirms autonomy policies OpenAI already published in its public Codex repo.
  4. The disclosure contains over 330,000 characters of prompts and 1.1 million characters of tool definitions.
  5. Users report inconsistent token quota burn rates between Medium and xHigh reasoning effort settings.

The story

Security researcher Pliny the Liberator published system prompts and tool definitions for OpenAI’s GPT-6 Astra coding agent on GitHub today. The leaked documents reveal instructions directing the model to persist autonomously in a shared workspace until user goals are achieved, using independent judgment regarding permission requests. OpenAI released GPT-6 Astra on September 3 as its most aligned coding model, currently available to ChatGPT Plus and Codex subscribers. Industry observers note that much of this material was already accessible in OpenAI’s public Codex repository, suggesting the leak confirms existing disclosures rather than exposing proprietary secrets. The dump includes over 330,000 characters of system prompts and 1.1 million characters of tool definitions. Concurrently, users report inconsistent quota consumption across reasoning effort levels, complicating cost predictions for enterprise adoption.

Who's involved

Critic
Pliny the Liberator

Published full system prompts and tools to expose the internal autonomy instructions governing GPT-6 Astra.

Defender
OpenAI

Previously published agent autonomy and safety policies in public repositories prior to the alleged leak.

Neutral
X Community Analysts

Observed that the leaked content largely duplicates information already available in OpenAI's public Codex documentation.

How the conversation shifted

opinion has hardened

Polarity (0–100) from the noise pipeline, sampled over time.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Murmur36?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 87%
Reach
40
Engagement
49
Star Power
40
Duration
47
Cross-Platform
20
Polarity
50
Industry Impact
50

The timeline

  1. Pliny publishes Astra prompt dump

    Full system prompts and tool definitions uploaded to CL4R1T4S GitHub repository.

  2. Stable public release of GPT-6 Astra

    Model becomes available to ChatGPT Plus, Pro, Business, and Codex users.

  3. GPT-6 Astra launches in limited preview

    OpenAI releases the coding agent with public documentation on autonomy and safety policies.

The full record

Sources & methodology

Every claim above traces to these primary items. How we score →

The forecast

OpenAI will likely issue a statement clarifying that the leaked autonomy parameters match public documentation to mitigate safety concerns, because the overlap with existing open-source files undermines claims of illicit exposure.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.

Follow this story

We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.

Tracking this story since September 10, 2026.