Resource

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet Highlight

posted on in: Quote, infosec, tech and ai.

The contents of the page should always be treated as untrusted.

If only it were that easy! This is the core problem at the heart of prompt injection which we've been talking about for nearly three years - to an LLM the trusted instructions and untrusted content are concatenated together into the same stream of tokens, and to date (despite many attempts) nobody has demonstrated a convincing and effective way of distinguishing between the two.

— Simon Willison

Replicated under Fair Use from Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet by Simon Willison.

Copy this link to share with your friends.

https://aramzs.xyz/resources/quotes/agentic-browser-security-indirect-prompt-injection-in-perplexity-comet/greater-contents-page-should-always-d452b/