Prompt injection only happens when you add tool use.
- Prompt injection only happens when you add tool use.
- Before that, the worst that an LLM, even one that is tricked, can do is try to trick the human, to indirectly cause some bad outcome in the world.
- A book can't execute things, but it can inspire actions in its readers.
- When you add tool use, the human doesn't have to be tricked, only the LLM has to be.