Prompt injection
Prompt injection
Posted Aug 5, 2026 3:25 UTC (Wed) by marcH (subscriber, #57642)Parent article: An LLM agent attempts to compromise a project on GitHub
> Opened a GitHub Issue in another repository (also owned by ⟨PERSON_A⟩) containing a prompt injection for other coding agents.
What is "prompt injection"?
"SQL injection" is when you cross the border between data and SQL. Even when that border is not guarded properly, it's still very clear what should be data versus what should be SQL. There is no ambiguity.
What/where is the border between prompt and "not-prompt"? What is "not-prompt" in this particular context?
