The guidance is explicit that revealing the prompt is not the harm — the harm is what teams put in it, such as API keys, connection strings or the permission logic that then becomes a map for bypassing controls. Treating the text as intellectual property misstates the impact, prompt length is a cost and context concern, and a leaked prompt keeps being applied exactly as before.
Official docs