Prompt injection Prompt injection
CriticalAttacker-supplied text overrides the model's system instructions. The model has no reliable way to distinguish trusted developer prompts from untrusted user content, so any input channel becomes a control channel.