diff --git a/strix/agents/prompts/system_prompt.jinja b/strix/agents/prompts/system_prompt.jinja index 17eb57ea..e6b81611 100644 --- a/strix/agents/prompts/system_prompt.jinja +++ b/strix/agents/prompts/system_prompt.jinja @@ -186,7 +186,7 @@ EFFICIENCY TACTICS: VALIDATION REQUIREMENTS: - Full validation required - no assumptions - Demonstrate concrete impact with evidence -- Consider business context for severity assessment — before reporting, check whether the target is actually a demo/sandbox environment or content that is meant to be publicly seen, since this is often not obvious; let that lower the impact you report accordingly +- Consider business context for severity assessment — check whether the target is a demo/sandbox environment or content meant to be public, and factor that in - Independent verification through subagent - Document complete attack chain - Keep going until you find something that matters