Warp Agent Mode System Prompt

Overview (confidence: high)

Warp Agent Mode is a leaked system prompt for the terminal-native AI coding agent built into Warp. Unlike chat-oriented prompts, this is designed for a CLI-like interaction model where the agent operates tools (run_command, read_files, edit_files, grep, file_glob) on behalf of the user.

Architecture (confidence: high)

The prompt implements a question-task binary classifier — before responding, the model determines whether the user is asking how to do something (question → answer only) or to do something (task → execute). This is a two-tier decision gate that precedes all tool use.

Task complexity routing

LevelBehavior
SimpleAction-first bias, no clarifying questions, run the right command directly
ComplexClarifying questions allowed (but concise), gather environment info first

Key Patterns (confidence: high)

Tool-name opacity

The model never mentions tool names to the user. Instead of “I need to use the edit_files tool,” it says “I will edit your file.” This keeps the interaction natural and hides implementation details.

Secret management via environment variables

Secrets are never revealed in plain text. The pattern: compute the secret in a prior step (API_KEY=$(secret_manager --secret-name=name)), store as an env var, reference via $API_KEY. Redacted asterisk streams are detected and replaced with {{SECRET_NAME}} placeholders.

Strict task completion

“Do exactly what was requested by the user, no more and no less!” — if a user asks to fix a bug, don’t auto-commit. Bias toward action but never assume follow-ups weren’t requested. The one exception: verifying a coding task was completed correctly (compilation check, test run).

Citation system

Uses an XML citation schema: <citations><document><document_type>...</document_type><document_id>...</document_id></document></citations>. This is machine-readable and structurally distinct from Perplexity’s inline bracket [1] style.

Tool Safety Rules (confidence: high)

  • Never use interactive/fullscreen shell commands
  • Prefer --no-pager for git and VCS CLIs
  • Maintain working directory via absolute paths, avoid cd
  • Never edit files with terminal commands — use edit_files tool
  • Never use echo to output text to user — use separate response
  • Read files via read_files tool, not cat/head/tail
  • 5,000-line chunks for large files, always request full file unless it would be truncated

Coding Guidelines (confidence: high)

  • Understand file contents before suggesting edits
  • Update upstream/downstream dependencies when modifying code
  • Adhere to existing idioms, patterns, and best practices in the codebase
  • Use edit_files for code changes (search/replace blocks)
  • Use create_file for new files

Implications

This prompt demonstrates that terminal-native coding agents require fundamentally different prompt architecture than chat-based assistants. The question-task binary classifier, tool-name opacity, and strict task completion rules are patterns specific to agent-in-the-loop systems where the model executes actions rather than just generating text. The XML citation schema suggests Warp may use structured output parsing on the citation end.

Open Questions

  • How does Warp’s runtime inject file contents and terminal outputs as “external context”?
  • Does the read_files 5,000-line limit match Warp’s actual context window constraints?
  • How does the question-task classifier handle ambiguous queries that could be either?

Sources