This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Prompt injection works because the agent acts on text it cannot verify. A new paper stops asking the agent to judge: it moves the authorization decision off the host, onto a signature the agent can neither read nor forge, and reports residual attack success falling to zero across 15 models.
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.