L5 · Talking to Models
Prompt Injection Is a Security Bug
Find the injection path in an app and pick a defense that is not a prompt.
Your app writes the rules. Then it glues in a web page, an email or a review that someone else wrote. Both land in the same flat string, and the model has no way to tell which half you trust.