> «It's very simple: prompt injection is a completely unsolved problem. As things currently stand, the only fix is to avoid the lethal trifecta.»
True, but we can easily validate that regardless of what’s happening inside the conversation - things like «rm -rf» aren’t being executed.