After building a free-for-all prompt myself (see profile), here’s how I protect against these attacks:
1. Whatever they input gets rewritten in a certain format (in our case, everything gets rewritten to “I want to read a book about [subject]”)
2. This then gets evaluated against our content policy to reject/accept their input
This multi layered approach works really well and ensures high quality content.