Output encoding still matters around LLMs
Model output going into a web page, a query or a command needs escaping exactly like any other untrusted text.
Teams frequently skip it because the text came from their own system, when in fact it was shaped by whatever the model read. The oldest defences in application security apply unchanged here, and the novelty of the component is what causes them to be forgotten.
More on Prompt injection
- Prompt secrecy does not solve prompt injectionSecret rules, open letterbox
- Retrieval content needs trust boundariesMaterial, never orders
- A model can leak data present in its contextIt can say what it can see
- Guardrails are layers, not one magic classifierMind the gaps, plural
- Telling the model to ignore attacks is not a hard boundaryPaint is not a barrier
- Human approval needs meaningful informationApprove what, exactly
