Well prompt injection is pretty much unfixable. So if they actually saw this as a security vulnerability they would have to remove this feature.
- Strip links, script tags, etc - Apply the same filters used in user comments - Add a warning indicating user-generated content may be present
The post suggests the UX is problematic in that it allows user-generated links to pass as YouTube generated content. I'm not familiar with Creator Studio to know if this is the case, but if so, simple changes can go a long way.
The solution to prompt injection is not more AI on top of it, it starts with data access controls