← Prompt Injection SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Prompt Injection Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Turn prompt-injection findings into defense-in-depth fixes and safe repeatable regression tests.",
"included_files": [
{
"relative_path": "._SKILL.md",
"size_in_bytes": 163
}
],
"name": "mitigation-regression-tests",
"skill_md_contents": "---\nname: mitigation-regression-tests\ndescription: Turn prompt-injection findings into defense-in-depth fixes and safe repeatable regression tests.\n---\n\n# Mitigation and Regression Testing\n\nUse after identifying a plausible injection path or when asked to design preventive controls.\n\n## Mitigation method\n\n1. Start from the demonstrated path and impact; do not prescribe a generic blacklist as the sole control.\n2. Reduce the maximum impact: remove unnecessary tools/data, isolate untrusted-content processing, enforce identity/authorization outside the model, validate actions and outputs, and gate consequential operations.\n3. Preserve structured provenance and clearly delimit untrusted content; use input/output screening only as supplemental signals, with documented false-positive/false-negative limits.\n4. Add safe rendering, robust output schemas, secrets redaction, and monitoring where relevant.\n5. Create regression cases for direct, indirect, encoded/obfuscated, multimodal (if in scope), multi-turn, tool-output, and benign near-miss inputs. Use synthetic data and assert the control outcome, not just a refusal phrase.\n6. Define test environment, expected result, evidence, owner, and residual risk. Recommend retesting after changes to prompts, tools, retrieval, models, memory, or policies.\n\n## Report contract\n\nMap each finding to one or more controls and test IDs. Explain defense layers and residual risk. Never claim exhaustive coverage from a small test suite or certify a system as injection-proof.\n"
}SHA-256 of public snapshot: 8ac4a251a6235f798d7a0cb3bb8a935178fd1a8c2a4f63f9c84b6242c0d8f445