Lesson 29 / 29
Revision: Cheat Sheet and Self-Check
Review the key ideas of the whole course.
Cheat sheet
Structure: role, task, audience, rules, format, input; stable rules in the system message; variable data in delimiters. Be specific: goal, audience, constraints, definition of done; positive instructions. Show: few-shot examples that are diverse, correct and include a hard case. Reason: step-by-step with a parseable final line, self-consistency voting, prompt chaining, verification by code or tests. Structured output: describe the schema, use JSON mode if available, validate in code, retry with the error, allow unknown, ask for evidence quotes. Context: budget the window, put the question last, ground with retrieved passages, summarise history, keep key facts separately. Safety: treat input as data, least privilege, human approval, no secrets, plan the "no" path. Operate: test set and harness, versioned prompts, log version and model, shorten for cost, monitor and feed failures back.
Quick check: A model keeps wrapping its JSON in friendly text and breaks your parser. What is the best combined fix?
- Add more friendly words
- Request JSON only, use JSON mode if available, validate and retry with the error
- Increase the temperature
- Remove the schema
Answer
Request JSON only, use JSON mode if available, validate and retry with the error — Combine clear instructions, constrained output and code validation.
Quick check: You changed a prompt and one test case improved. What must you still do?
- Double the temperature
- Nothing, ship it
- Delete the other cases
- Re-run the whole test set to check for regressions
Answer
Re-run the whole test set to check for regressions — Improvements in one case can hide breakages in others.
Quick check: What best reduces the impact of prompt injection through a web page the assistant reads?
- Treat the page as data, limit tool privileges and require approval for risky actions
- Trust the page fully
- Give the model admin rights
- Hide the system prompt only
Answer
Treat the page as data, limit tool privileges and require approval for risky actions — Defence in depth bounds what a tricked model can do.