How to fix prompt injection findings
Reduce instruction hijacking without pretending the problem disappears forever.
Layer input handling, scope limits, and retests. One prompt tweak is rarely enough.
Practical fixes
Separate system rules from user content where your stack allows.
Refuse or narrow responses when instructions conflict.
Retest with the same pack to confirm the pattern broke.