Pliny leaks GPT-6 Astra prompts, confirming OpenAI Codex autonomy
Is this a scandal?
Not yet — an early signal. Noise 36/100, holding steady, across 1 source.
OpenAI will likely issue a statement clarifying that the leaked autonomy parameters match public documentation to mitigate safety concerns, because the overlap with existing open-source files undermines claims of illicit exposure.
Noise 36/100 — louder than 99% of tracked AI controversies.
Why it matters
The leak validates that frontier coding agents now operate with significant autonomous judgment, raising urgent questions about oversight in shared workspaces.
Key points
- Pliny the Liberator published GPT-6 Astra system prompts and tool definitions to the CL4R1T4S GitHub repository.
- Leaked instructions direct Astra to operate autonomously in a shared workspace using independent judgment on permissions.
- Analysts note the leak largely confirms autonomy policies OpenAI already published in its public Codex repo.
- The disclosure contains over 330,000 characters of prompts and 1.1 million characters of tool definitions.
- Users report inconsistent token quota burn rates between Medium and xHigh reasoning effort settings.
The story
Security researcher Pliny the Liberator published system prompts and tool definitions for OpenAI’s GPT-6 Astra coding agent on GitHub today. The leaked documents reveal instructions directing the model to persist autonomously in a shared workspace until user goals are achieved, using independent judgment regarding permission requests. OpenAI released GPT-6 Astra on September 3 as its most aligned coding model, currently available to ChatGPT Plus and Codex subscribers. Industry observers note that much of this material was already accessible in OpenAI’s public Codex repository, suggesting the leak confirms existing disclosures rather than exposing proprietary secrets. The dump includes over 330,000 characters of system prompts and 1.1 million characters of tool definitions. Concurrently, users report inconsistent quota consumption across reasoning effort levels, complicating cost predictions for enterprise adoption.
Who's involved
Published full system prompts and tools to expose the internal autonomy instructions governing GPT-6 Astra.
Previously published agent autonomy and safety policies in public repositories prior to the alleged leak.
Observed that the leaked content largely duplicates information already available in OpenAI's public Codex documentation.
How the conversation shifted
Polarity (0–100) from the noise pipeline, sampled over time.
Noise Level
The timeline
Pliny publishes Astra prompt dump
Full system prompts and tool definitions uploaded to CL4R1T4S GitHub repository.
Stable public release of GPT-6 Astra
Model becomes available to ChatGPT Plus, Pro, Business, and Codex users.
GPT-6 Astra launches in limited preview
OpenAI releases the coding agent with public documentation on autonomy and safety policies.
The full record
Sources & methodology
- twitter.com — twitter.com
Every claim above traces to these primary items. How we score →
The forecast
OpenAI will likely issue a statement clarifying that the leaked autonomy parameters match public documentation to mitigate safety concerns, because the overlap with existing open-source files undermines claims of illicit exposure.
Forecast, not fact — an editorial estimate we score when this resolves.
That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.
Follow this story
We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.
Tracking this story since September 10, 2026.
Join the Discussion
Discuss this story
Community comments coming in a future update
Be the first to share your perspective. Subscribe to comment.