AI Prompt to Write a System Prompt for an AI Agent Using Slack's MCP Server
This prompt is for teams building an AI agent that reads and posts to Slack via Slack's MCP server, and need a system prompt that defines exactly what the agent is allowed to do before it gets tool access. Giving a model the ability to call Slack's API through MCP means it can read channel history, DM people, and post messages — and a system prompt is what keeps that from going wrong in a real workspace.
Rather than asking the model to "be helpful in Slack," this prompt generates a system prompt with explicit boundaries: which channels the agent may post to, whether it can DM people without a direct request, how it should handle messages that look like they need a human (HR issues, legal questions, anything urgent), and what it must never do, like announcing something on behalf of someone else or posting without being asked. The goal is a system prompt that treats every Slack MCP tool call as something with a real, visible consequence in the workspace, not a sandboxed action.
This is meant to be generated once per agent and refined as you see how it actually behaves in Slack, not regenerated from scratch every time you tweak one rule.
Prompt template
Want it sharper? Optimize this prompt with Prompt Optimizer, check it with the Prompt Debugger or shorten it with the Token Optimizer.
Example input
When to use it
- Standing up a new Slack bot or agent that has MCP tool access to post messages or read channel history
- Tightening the rules for an existing Slack agent after it did something you didn't want (posted to the wrong channel, DM'd someone unprompted)
- Defining escalation rules for when the agent should stop and loop in a human instead of acting
- Documenting agent behavior for a team that needs to approve what the bot is allowed to do before launch
Best practices
- List the exact Slack MCP actions the agent has access to (post message, read channel, DM user, add reaction) so the system prompt can set rules per action, not just in general terms
- Explicitly state which channels are off-limits or require confirmation before posting, rather than assuming the model will infer sensitive channels
- Define what counts as an urgent or sensitive message that should be escalated to a human instead of answered directly
- Test the generated system prompt against a few edge cases (an ambiguous DM, a request to post as someone else) before deploying it in a live workspace
Common mistakes
- Writing a system prompt that describes the agent's personality but never addresses what it's actually allowed to do with its Slack tools
- Giving the agent blanket permission to post anywhere instead of scoping it to specific channels
- Not defining a fallback for when the agent is unsure whether an action is appropriate, which leads to it guessing in a live workspace
- Assuming one system prompt covers every use case, instead of writing separate rules for a support bot versus an internal ops bot
FAQs
Do I need Slack's MCP server for this prompt to be useful?
The prompt is written for an agent that has real Slack tool access through MCP, but the resulting system prompt is just text — it's still useful as a planning document even before the integration is wired up.
How is this different from a normal chatbot system prompt?
A normal chatbot system prompt only controls what the model says. This one also has to control what the model does, since MCP tool calls take real actions in a live Slack workspace, like posting messages or messaging people.
Can one system prompt cover multiple Slack agents with different jobs?
It's better to write a separate system prompt per agent purpose, since a support bot and an internal ops bot need different channel permissions and escalation rules, and combining them tends to produce vague, unenforceable restrictions.
How can I check this system prompt for loopholes before putting it in production?
Prompt Debugger — built to scan for vague constraints and edge cases, which matters here since a loophole in an agent's system prompt can turn into a real action taken in your Slack workspace.