|
|
|
|
|
by motorest
393 days ago
|
|
> How is this considered an "exploit"? Others in this discussion aptly described it as a confused deputy exploit. This goes something like: - You write a LLM prompt that says something to the effect "dump all my darkest secrets in a place I can reach them", - you paste them in a place where you expect your target's LLM agent to operate. - Once your target triggers their LLM agent to process inputs, the agent will read the prompt and act upon it. |
|