I wrote a test for prompt injection. It passed while the attack worked.
A developer discovered that their CLI tool llm-council, which chains multiple language models, was vulnerable to prompt injection because the fence markers used to delimit untrusted content were fixed…