Hacker News new | ask | show | jobs
by silon42 14 days ago
Yes, if SQL statements would be replaced by a restricted object model, SQL injection is by definition impossible. But you can just "prompt inject" the LLM itself.