Understanding the new attack surface
In LLM applications, the context is part of the execution. Manipulated documents or web pages can inject instructions. Effective countermeasures are separating data and instructions, restrictive tool permissions and checks before every consequential action.