We are several years into this and the biggest companies peddling these tools still cannot figure out how to make their products not fall for advanced cyberattack techniques like *checks notes* asking nicely again.
Microslop Slopilot had (has?) a similar issue – Reprompt attack simply repeated the malicious prompt in a query parameter:
https://www.techrepublic.com/article/news-reprompt-attack-microsoft-copilot/
These are not going away.
