Skip to content

Prompt Injection

Why no parser separates instructions from data, where untrusted text enters, why delimiters are not a boundary, and how to design so a landed instruction cannot do damage.

10 lessons · about 91 minutes

What you'll go through

  • 01The support ticket told your agent what to do9 min
  • 02Why there is no library that solves it9 min
  • 03Every tool result is somebody else's writing9 min
  • 04Nobody attacked you; they attacked a page you read9 min
  • 05You wrapped it in tags and it still worked9 min
  • 06What a classifier catches, and what walks past it9 min
  • 07Assume the instruction lands. Now what?9 min
  • 08One poisoned document, two agents9 min
  • 09Where did that instruction come from?9 min
  • 10Writing down what your agent can be made to do10 min