This is why I wrote https://github.com/gregretkowski/llmsec . Every LLM system should be evaluating anything coming from a user to gauge its maliciousness.
But if this secondary LLM is able to detect this, wouldn't the LLM handling the input already be able to detect the malicious input?