John McBride @johncodes.com · Feb 20

I advise extreme caution using xAI's Grok, especially for programmatic or agentic uses - it appears they have nearly no prompt injection mitigation. 1. Very basic prompt injection attacks work, even when it attempts to use one of its tools, it still falls back to the user provided prompt:

2 likes 1 replies

?

Replies

John McBride · Feb 20

2. Exfiltrating it's system message (or at least the contents of its system message) was fairly easy: