Skip to content

security(llm): mitigate prompt injection via spec/file content (F-11) #6

@gibbon

Description

@gibbon

User-supplied spec values and file contents are inlined into draft/enrich prompts. Wrap them in delimited blocks (e.g. <USER_SPEC>...</USER_SPEC>) and document the inherent LLM-prompt-injection risk in docs/llm.md. See F-11.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions