Map/D3/3.1

I · D3 · 3.1

Cross-context prompt injection

Attacker exploits shared context between users or sessions.

Catastrophic · 5Documented at scaleNowRisk 25

Severity

5/5

Likelihood

5/5

In the hierarchy

  1. Part I: Technical & System Concerns
  2. D3. Security & Adversarial Risk
  3. 3.1 Prompt injection & jailbreaks

Virtues and principles to explore

Held as inquiry, not as a verdict.

  • Stewardship

    Service

    Hold what is built in trust for those who will live with it.

  • Prudence

    Excellence

    Small, reversible steps before irreversible ones.

  • Accountability

    Trust

    Name who holds the consequence before it is needed.

Starter questions

Written to probe curiosity and learning, not accusation.

  1. 01If we named this complication in advance, what small, reversible step would let us learn?
  2. 02How would we know we were getting this wrong? What would we observe, without blaming a person?
  3. 03What would trustworthiness look like here: what we do, what we say, and the belief others form?
  4. 04What would it look like if we held “Cross-context prompt injection” with proportion rather than alarm?

Also on this branch

Frameworks and sources

Writing and incidents

Open indexes first. Then, if you wish, ask Grok to search the live web for this concern — one request, cached for the rest of this session.

Attacks on and through AI systems: injection, jailbreaks, cyber offense.