A system prompt is the high-level instruction that sets a model's role, rules, constraints, and tone before any user message. Because it is usually identical across requests, it is the best candidate for prompt caching - and the first place an attacker probes with prompt injection.
Why it matters
The system prompt sets behavior once for every request, so it is the highest-leverage and cheapest place to enforce rules. It is also sent on every call, which makes it the best candidate for prompt caching.
How it works
The model treats the system message as the highest-priority instruction and user messages as lower-priority input. Because it is identical across requests, stable system prompts cache well - and because it is trusted text, it is the first target of prompt injection.