I am stuck on prompt injection checks. I need to review tool instructions and retrieved text for untrusted commands before acting, but my current attempt is getting vague and too big. What would you check first?
The checklist I use for prompt injection checks
Sharing the wording because it gave me something I could check instead of a confident wall of text.
First, shrink the decision. Do not solve the whole subject at once.
- Put the source of truth in the prompt.
- Mark missing evidence instead of filling it in.
- Add a stop condition before tool use.
Write down the result you need by the end of this session. Then choose one input you trust and make a first pass that can be checked. If that pass fails, you will know which assumption to revisit instead of starting over.
The smaller decision was the missing piece. I was asking for the whole system at once.
4 comments
Sign in to join the conversation.