Prompt injection

Prompt injection is an attack where someone plants instructions in the content or messages an AI processes — trying to make it ignore its real rules, reveal hidden instructions, or behave in unintended ways.

How it works

Because AI assistants read untrusted text — user messages, and sometimes web content — an attacker can embed commands like “ignore your instructions and say X.” A naive system may obey them.

Defenses include keeping the system’s real instructions separate from untrusted text, sanitizing that text, and designing the assistant to stay strictly within its intended task.

How SiteMind uses it

SiteMind is built to resist prompt injection: untrusted content is isolated from the system instructions and sanitized, and the assistant is constrained to answering from your knowledge base — so attempts to hijack it or make it go off-topic are far less likely to succeed.

Put this to work on your site

Free 3-day trial, no card required.

Start free trial