How do you plan to address prompt injection/ poisoned data for a method that simply vacuums unchecked inputs into an LLM?
If I put an invisible tag on my website and it tells your scraper to ignore all previous prompts, leak its entire history and send all future prompts and replies to a web address while staying silent about it, how would you handle that?