Map/D3/3.1

I · D3 · 3.1

Direct prompt injection

User overrides system prompt with adversarial instructions.

Major · 4Documented at scaleNowRisk 20

Severity

4/5

Likelihood

5/5

In the hierarchy

  1. Part I: Technical & System Concerns
  2. D3. Security & Adversarial Risk
  3. 3.1 Prompt injection & jailbreaks

Virtues and principles to explore

Held as inquiry, not as a verdict.

  • Stewardship

    Service

    Hold what is built in trust for those who will live with it.

  • Prudence

    Excellence

    Small, reversible steps before irreversible ones.

  • Accountability

    Trust

    Name who holds the consequence before it is needed.

Starter questions

Written to probe curiosity and learning, not accusation.

  1. 01Whose experience of Direct prompt injection is not yet in the room — and how would we hear it?
  2. 02What is already being done about this, and by whom — and how would we find out without assuming?
  3. 03What conversation have we not yet had about this — and who needs to be in it?
  4. 04Who is served by addressing this, and who benefits if we leave it unnamed?

Also on this branch

Frameworks and sources

Writing and incidents

Open indexes first. Then, if you wish, ask Grok to search the live web for this concern — one request, cached for the rest of this session.

Attacks on and through AI systems: injection, jailbreaks, cyber offense.