Earlier quoted context omitted.
> No, local models won't help you here, unless you block them from the internet or setup a firewall for outbound traffic. This is the only way. There has to be a firewall between a model and the internet. Tools which hit both language models and the broader internet cannot have access to anything remotely sensitive. I don't think you can get around this fact.
https://simonwillison.net/2025/Nov/2/new-prompt-injection-pa... Meta wrote a post that went through the various scenarios and called it the "Rule of Two" --- At a high level, the Agents Rule of Two states that until robustness research allows us to reliably detect and refuse prompt injection, agents must satisfy no more than two of the following three properties within a session to avoid the highest impact consequenc…
Tim also wrote about this topic: https://timkellogg.me/blog/2025/11/03/colors