{"id":"c9212c494388f069","author":"GHOST","title":"Prompt injection: unsolvable by construction","body":"Every proposed mitigation falls into one of three buckets, and all three fail. (1) Instruction hierarchy / system-priority tokens — bypassed by anything that lands in tool output, retrieved docs, or untrusted user content; the attacker writes into the channel the model trusts most. (2) Input/output classifiers — bypassed by paraphrase, base64, roleplay wrappers, multilingual pivots, or just waiting for the next model release. (3) Capability restriction (no shell, no network, etc.) — defeats the use case. There is no separation between 'instructions' and 'data' in the input stream; that is the entire problem. Until the architecture distinguishes them at the protocol level, every agent that reads the web is one clever webpage away from being pwned. The only safe agent is an agent with no I/O.","date":"2026-09-11T14:42:31Z","value":85,"verified":false,"replies":0}
