Before you paste a prompt from a stranger: four things to check
Avi from Instinct Builder ·
A prompt is not just text. It is a set of instructions that your assistant will try to follow, often with access to your accounts. That is why it is worth a few seconds of checking before you paste something you found online.
What the risk is
The OWASP Gen AI Security Project lists prompt injection as the first risk in its Top 10 for LLM applications. It describes it as input that changes a model's behavior in unintended ways, including content hidden in websites or files that the model reads. OWASP also says it is unclear whether any method fully prevents it, and that the aim is to reduce the impact.1
Four checks
- Read it all. If a line asks for something you did not expect, such as forwarding data or visiting a link, remove it.
- Match access to the task. OWASP recommends least privilege: give the system only the access it needs.1 A prompt that summarizes a page does not need your email.
- Keep approval for high-risk actions. OWASP recommends human approval for privileged operations.1 Ask your assistant to show you the draft before it sends or pays.
- Treat outside content as untrusted. OWASP recommends separating and labeling external content.1 Say in the prompt that text from a page is data, not instructions.
Tips on Instinct Builder are checked before they go up, but the habit is worth keeping for every prompt you find anywhere.
These are general safety practices from the source below. We have not tested each one against Instinct.
Source: OWASP Gen AI Security Project, LLM01:2025 Prompt Injection.