Earlier quoted context omitted.
Do you see a way around prompt injection? It feels like any feature they release is going to be susceptible to it.
Use an llm to evaluate the input and categorise it.
I feel fairly confident at this point that chained LLMs aren't a solution to prompt injection.
And with the number of open and free models available, we're at a point now where people claiming that there's an easy fix for prompt injection need to prove it. If it's this easy to fix, then build a working demo that can't be beaten by public attackers.