AI Security Goes Beyond Prompt Injection episode artwork

EPISODE · Jun 17, 2026 · 54 MIN

AI Security Goes Beyond Prompt Injection

from System Prompt · host Peter

READ THE FULL EPISODE PAGEhttps://devmesh.tech/podcast/ai-security-beyond-prompt-injectionAI security involves more than filtering bad prompts.In Episode 14 of System Prompt, Peter and Val examine the expanding attack surface created by large language models, AI agents, tools, retrieval systems, and external integrations.The discussion covers prompt injection, jailbreaks, system prompt extraction, context poisoning, supply-chain attacks, MCP and tool poisoning, sensitive information disclosure, and the defensive controls needed to reduce risk.The central point is simple: no system prompt or single filter can secure an AI application by itself.WHAT WE DISCUSS• Direct and indirect prompt injection• Skeleton key and crescendo jailbreaks• Context compliance attacks• System prompt extraction• Context and retrieval poisoning• Supply-chain attacks• Tool and MCP poisoning• Sensitive information disclosure• Instruction hierarchy and policy enforcement• Observability, testing, and defensive frameworksKEY TAKEAWAYSPROMPT INJECTION IS ONLY ONE ATTACK PATHMalicious instructions can enter through user input, retrieved documents, webpages, emails, tool responses, memory, or external integrations.Security must cover the entire pipeline, not only the chat interface.UNTRUSTED DATA SHOULD NOT BECOME INSTRUCTIONSAI systems combine system rules, user requests, retrieved content, and tool output.The system must distinguish trusted instructions from untrusted information.Retrieved documents should be treated as data, not authority.TOOLS INCREASE THE CONSEQUENCES OF FAILUREA compromised model response becomes more dangerous when the system can access files, send messages, modify records, execute commands, or call outside services.Tools need least-privilege permissions, strict schemas, validation, and approval boundaries outside the model.OBSERVABILITY IS A SECURITY REQUIREMENTTeams need visibility into prompts, retrieved context, routing, tool calls, permissions, outputs, and failures.Without tracing, it may be impossible to determine whether a bad result came from the model, poisoned context, or an unsafe integration.SECURITY REQUIRES LAYERSUseful defenses include access controls, input handling, output validation, sandboxing, allowlists, retrieval filtering, rate limits, testing, monitoring, and human approval for high-risk actions.No single control will stop every attack.CHAPTERS00:00 — Celebrating Episode 1405:14 — Prompt Injection and Defense12:47 — Crescendo Jailbreak17:51 — Context Compliance Attacks34:24 — System Prompt Extraction41:27 — Supply-Chain Attacks48:20 — Sensitive Information DisclosureWATCH THE EPISODEhttps://youtu.be/X2UCeQQVWtcABOUT SYSTEM PROMPTSystem Prompt covers AI infrastructure, automation, agents, local models, enterprise platforms, security, and practical implementation.

Episode metadata supplied by the publisher feed · Published Jun 17, 2026

Embed this episode

Ready to play

AI Security Goes Beyond Prompt Injection

0:00 54:07

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of System Prompt?

This episode is 54 minutes long.

When was this System Prompt episode published?

This episode was published on June 17, 2026.

Can I download this System Prompt episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!