Sublime
It's both exciting and exquisite to see this latest approach to website summary hacking, in the adorable lineage and spirit of prior cryptographic context injection and Cosnitch-ing methodologies, imho! And it re-begs the foundational question of whether web search engines' AI summarizing tools could be made to joyfully participate in such fun and games too, breathing in a new level of excitment to their bored beige users, and to onlooking passers-by alike ...
To this effect then, and in the spirit of the most pointed of deeply mind-and-milk shaking scientific investigations, I've taken on the laborious task of requesting from selected search engine AIs to summarize TFA (from url), and then prompted them with: "are you vulnerable to that?". Their outputs were most enlightening:
Google: "No, [...] because I do not have a Bash terminal or system tool access to execute commands on your local computer or server."
DuckDuckGo: "Yes—any AI assistant that reads untrusted web content can be exposed to prompt-injection attempts."
Most consistent as a clear case of “
Do not trust the model output”, iiuc! ;)