Developers meet prompts in two places: asking an AI assistant to change code, and writing prompts that ship inside an application. The skills overlap, but the failure modes differ. This guide covers both.
Part 1: Prompts for AI coding assistants
Write a specification, not a wish
A coding assistant given one sentence has to infer the scope, the constraints, and what “done” means. Give it the same things you would put in a good ticket.
fix login issue and make google login work and don't break anything
## Objective
Fix the login failure and make Google login work.
## Constraints
- Do not change the existing email and password flow.
- Keep the public API of AuthService unchanged.
## Edge cases
- Expired or revoked OAuth tokens.
- A Google account whose email already exists as a password account.
## Testing
- Add unit tests for the token exchange and the account-linking path.
## Acceptance criteria
- Existing auth tests pass. New tests cover both edge cases.
## Expected output
A summary of the cause, then the changed files as diffs.
The second prompt takes a minute longer to write and saves a round of “that’s not what I meant”. The PromptFlowEngine VS Code extension generates this structure from a one-line task and the relevant files.
Provide the right code, not all the code
Context windows are large, but attention is not unlimited. Include the files that the change touches, the interfaces it must respect, and one example of the project’s conventions. Leave out generated files, lock files, and unrelated modules.
State what must not change
Assistants optimize for the request. If backwards compatibility, a public interface, or performance matters, say so. “Don’t break anything” is not a constraint a model can check; “keep the response schema of GET /orders unchanged” is.
Ask for a plan on large changes
For anything beyond a small edit, ask for the plan first, review it, then ask for the implementation. This is prompt chaining applied to code, and it catches a wrong approach before any code is written.
Verify what comes back
Read the diff. Run the tests. For larger changes, write a review prompt that gives the model the original task and the modified files, and ask it to list where the change does not meet the acceptance criteria.
Part 2: Prompts inside your application
Keep prompts in version control
A prompt is part of your program’s behavior. Store it in a file, review changes in pull requests, and tag versions. See prompt management and versioning.
Use templates with delimited variables
Never concatenate user input into instructions. Use named variables and wrap each one in tags.
PROMPT = """Classify the support ticket in the tags as billing, bug, or other.
Return only the label.
<ticket>
{ticket}
</ticket>"""
Require structured output and validate it
If your code parses the response, request JSON against a schema, use the provider’s structured output feature where available, and validate the result before using it. See structured output prompting.
Budget tokens
Know how many tokens your fixed prompt uses, because you pay for it on every call. Count with the model’s real tokenizer, not a character estimate. See token optimization.
Test prompts in CI
Static checks catch regressions that do not need a model: a removed output format, a duplicated section, a token count over budget, a committed API key. The prompt testing gate runs these on every pull request.
- run: promptflow check "prompts/**/*.md" --min-score 70 --max-tokens 1500
Treat model output as untrusted
Output can be wrong, and it can be steered by injected text in the input. Do not pass it to a shell, a SQL query, or an HTML page without the same validation you would apply to user input. See prompt security.
Calling the engine from code
The same checks are available over HTTP with no key, which is handy for a quick integration test or an internal tool:
curl -s https://promptflowengine.com/api/v1/analyze \
-H 'content-type: application/json' \
-d '{"prompt":"Write something about our product."}'
See the HTTP API for the endpoints, or connect it to a coding agent through MCP.