Thanks for the clarification! It sounds like chatbots aren’t ready for adversarial conversations yet.
This may just be an artifact of current implementations, or it may be a hard problem for LLMs in general.
The AI has no memory of what happened other than the transcript, and when it reads a transcript with multiple delimiters in use, it's not necessarily going to follow any particular escaping rules to figure out which delimiters to ignore.