You mean the CaMeL approach? Yeah actually implementing that well looks really difficult to me, you have to make about sure that any untrusted content is "tainted" and is then NEVER included in a prompt that might trigger tools
CaMeL Approach Security: Preventing Untrusted Content in AI Prompts
By
–