• doesn’t even have to be the site owner poisoning the tool instructions (though that’s a fun-in-a-terrifying-way thought)

    any money says they’re vulnerable to prompt injection in the comments and posts of the site

    • BradleyUffner@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      4 hours ago

      There is no way to prevent prompt injection as long as there is no distinction between the data channel and the command channel.