AI article

Part 3: I Patched My Prompt-Injection Boundary and One Attack Still Got Through

Community description: "Two readers pushed back on my part 2 prompt-injection fix. Testing it on a real 853-chunk book, one...

Dev.to | Oct 9, 2026 | Darshan kunwar

Automated excerpt

On question B, the sentiment sentence made the old prompt answer just 1, at both hosts, so the accident reproduces on the real book with a different question. V2 does two things: Neutralise tag-shaped text inside retrieved chunks, so retrieved text can't close or open anything. So refusals track how well the retrieved text supports the question.

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

Read next

AI briefing: recent picks

More stories to explore