I’ve spent the past week locked in a room (figuratively, mostly) building a solution for a problem that’s been bugging me since the last AI security hackathon: prompt injection . We all know the standard way to protect an LLM agent. You put up a filter.