4 ms·
It seems like this collection of tools gives you a ton of lethal-trifecta risk for prompt injection attacks. How have you mitigated this—are you doing something
by amonks 1y ago
It seems like this collection of tools gives you a ton of lethal-trifecta risk for prompt injection attacks. How have you mitigated this—are you doing something like CaMeL?
- hgaddipa001 1y agoWe do a lot of processing on our backend to prevent against prompt injection, but there definitely still is some risk. We can do better on as is always the case. Need to read up on how CaMel does it. Do you have any good links?
- amonks 1y agoThat’s a pretty scary answer, to be honest. Regardless, here’s the CaMeL paper. Defeating Prompt Injections by Design (2025): https://arxiv.org/abs/2503.18813 https://arxiv.org/abs/2503.18813 Here’s a paper offering a survey of different mitigation techniques, including CaMeL. Design Patterns for Securing LLM Agents against Prompt Injections (2025): https://arxiv.org/abs/2506.08837 https://arxiv.org/abs/2506.08837 And here’s a high-level overview of the state of prompt injection from 'simonw (who coined the term), which includes links to summaries of both papers above: https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
- hgaddipa001 1y agoThanks! Don't worry have worked with a few friends experienced in prompt injection to help with the platform. But will read these too :)
- ares623 1y agoRe: CaMeL, Jesus, why not build a UI with explicit access controls at that point?
- milkshakes 1y agobecause you can't enjoy your pina coladas on the beach if your phone keeps buzzing every 10 seconds.