The fact
The mode only blocks the final step of exfiltration and does not fundamentally solve prompt injection vulnerability
This limitation highlights that prompt injection remains an unresolved security issue in LLMs
Click the link to read an article on the topic: