These prompt injection vulnerabilities give me the heebie jeebies. LLMs feel so non deterministic that it appears to me to be really hard to guard against. Can someone with experience in the area tell me if I'm off base?
Allowing agent to run wild with any arbitrary shell commands is just plain stupid. This should never happen to begin with.