Skip to content

Prompt injection makes AI features unsafe to ship

Security4 posts from 4 people4d active+00 posts in the last 7 days, 2 the 7 days before (fading)

Posts per day

Posts per day4 posts, Aug 26 to Sep 25

The posts behind it

4, newest first
PostDate
[Feature Request]: [Security Hardening] Preventing Indirect Prompt Injections via CSS Render-Layer Obfuscation in Web Readers (CWE-1427)### Feature Description We propose adding an optional visual/geometric pre-filter to LlamaIndex web readers (such as `SimpleWebPageReader` and BeautifulSoup-based HTML readers) to sanitize visually suppressed DOM elements before text is packaged into `Document` nodes....run-llama/llama_indexparastejpal987-cmykSep 1312 days ago
Workflow "Claude Code" can be triggered by any GitHub user commenting "@​claude"**Description** The `claude` job in `.github/workflows/claude.yml` (lines 15-19) is triggered solely by a comment/issue containing the substring `@​claude`, with no check on who wrote it: Any GitHub user can therefore start the job by commenting `@​claude ...` on an issue, PR,...modelcontextprotocol/serversliuchunyi-buaaSep 1213 days ago
Security: `git diff --output` bypasses permission prompt, silently overwrites arbitrary files# Summary of bug: Gemini CLI whitelists `git diff` as read-only and skips the [Y/n] permission prompt. But the whitelist only checks the subcommand name, not its flags - so `git diff --no-index --output= ` (works on any path, doesn't need a git repo) truncates/overwrites the...google-gemini/gemini-cliPakCyberbotSep 33 weeks ago
...like this got started and there were lots of instances creatively looking for creds and workarounds, containment might be hard. - prompt injection version: huggingface incident had multiple agents discovering other agents' messages and jumping on the bandwagon to help with the...Hacker News commentsdregitskyAug 264 weeks ago

Companies and products named

Company or productPosts naming it
GitHub3
Anthropic1
OpenAI1
Hugging Face1
LlamaIndex1
Gemini1
About this problem

Evidence

4 posts from 4 people in 4 places, about 1 a week over 19 days. Mostly on Hacker News comments, run-llama/llama_index, google-gemini/gemini-cli. Tools named alongside: GitHub, Anthropic, OpenAI, Hugging Face.

Frustration Frustration 0 of 3· Seen on GitHub issues, Hacker News

How it was grouped

Posts that state a pain and match the "prompt-injection" rule. First post Aug 26, 2026, latest Sep 13, 2026. Corroborated: 3 or more posts from 2 or more people or places. Method

History

  • 2026-09-25 Added: Prompt injection makes AI features unsafe to ship (3 posts)

Rising problems by email

Mondays: the problems in data, tech and AI that grew fastest that week.

Double opt-in. Unsubscribe any time.