Prompt injection: direct, indirect, and how to contain both
Why it cannot be patched at the model layer, what an indirect payload hidden in a document actually looks like, and why the containment boundary has to sit outside the thing being attacked.
Read on prompt injection
