Hacker News new | ask | show | jobs
by rowborg 961 days ago
That was also my first thought (injection all the way down), but doesn't this reduce the problem to enforcing simple character escaping?
1 comments

You can inject prompts by having text hidden in images, simple escaping will not save you.