Hacker News new | ask | show | jobs
by simonw 52 days ago
It doesn't work. You can't trust LLMs to 100% reliably obey delimiters or structure in content. That's why prompt injection is a problem in the first place.