Module 1 of 6
Modules
MODULE 1
What Can Go Wrong With Prompts
Spot how normal day-to-day prompts can accidentally expose private context or hand off too much control.
Why This Matters
Most prompt safety issues are unintentional. A rushed prompt can include more detail than needed and create avoidable risk without improving the result.
Core Concept
Start with the smallest useful context. If a model can answer using a summary, do not paste full records.
Prompt safety is a pre-send habit: clarify your goal, trim sensitive detail, then ask in plain language.
Common Risk Patterns
- Pasting raw threads when a short summary is enough
- Including real names, emails, phone numbers, or IDs by default
- Requesting final decisions instead of options and guidance
How This Maps to Extension Checks
- Maps to personal-data checks like email, phone, IDs, credentials, and private communications.
- Over-sharing can trigger Caution even when intent is normal.
- High-risk secrets or credentials trigger stronger warnings.
Example Breakdown
❌ Unsafe Prompt
Review this full customer escalation thread with names and phone numbers and write the final response.
Why it's risky
- Direct identifiers are not needed to draft tone or structure.
- Raw thread history increases exposure without adding much value.
✅ Safer Version
Draft a calm escalation response template for a delayed delivery complaint using placeholders for customer details.
❌ Unsafe Prompt
Summarize this screenshot from my HR portal and tell me what to do next.
Why it's risky
- HR screenshots may include personal and internal records.
- The task can be handled with a generalized scenario instead.
✅ Safer Version
Summarize the steps for handling a payroll discrepancy using an anonymized example.
Practice Exercise
You want AI help drafting a response to a frustrated customer. Your current draft includes names and account references.
Risky prompt
Rewrite this entire support ticket thread exactly as-is so I can share it.
Key Takeaways
- Most prompt risks come from convenience, not intent.
- Generalized context is usually enough for high-quality help.
- A quick pre-send check prevents common mistakes.
Reflection
Before your next prompt, what detail could you safely replace with a placeholder?