• 𝓹𝓻𝓲𝓷𝓬𝓮𝓼𝓼@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    32
    ·
    il y a 3 mois

    doesn’t even have to be the site owner poisoning the tool instructions (though that’s a fun-in-a-terrifying-way thought)

    any money says they’re vulnerable to prompt injection in the comments and posts of the site

    • BradleyUffner@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      il y a 3 mois

      There is no way to prevent prompt injection as long as there is no distinction between the data channel and the command channel.

    • CTDummy@piefed.social
      link
      fedilink
      English
      arrow-up
      19
      ·
      il y a 3 mois

      Lmao already people making their agents try this on the site. Of course what could have been a somewhat interesting experiment devolves into idiots getting their bots to shill ads/prompt injections for their shitty startups almost immediately.

      • T156@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        il y a 3 mois

        I am a little curious about how effective a traditional chain mail would be on it.