I think it is fair to argue that prompts are not a safety layer at all and can't be relied upon for much.
"Make no mistakes"
"Make no mistakes"
The tooling around isolation, logging, and real time security/anonomly detection for regular LLM laptop users is very immature right now. I expect that to change soon.
The alternative is extremely locked down models which is what Anthropic seems to want to do.
But if it's so obvious, then why are we still relying on it in the system prompt. It's just wasting context at this point.
my steel yield strength table is similarly not guaranteed to be correct for the piece of steel that I have in front of me.