haha this reminds me that at one point during internal testing of Brave's AI agent (Leo), it refused to execute Step 3 on a todo list when Steps 1 and 2 were black text and Step 3 was white text (therefore invisible). but it got tricked into executing it when Steps 1 and 2 were
Indirect prompt injection is a fundamental security challenge for AI. It's an issue for both local and cloud-based LLMs.
After disclosing our findings to both companies, we're now sharing our analysis of Mozilla Tabstack and Cotypist today.
in light of the tragic news that a 2-year old died at a licensed SF daycare earlier this month, i made a site to show childcare license violations and complaints in the Bay Area: