Prompt injection: why there is no definitive fix, and what to do anyway
Twelve prompt injection defenses reporting near-zero rates were broken above 90%. Why the problem is structural and what reduces risk.
- prompt injection
- agent security
Page 2 of 4
Twelve prompt injection defenses reporting near-zero rates were broken above 90%. Why the problem is structural and what reduces risk.
The list of git operations auto mode refuses on its own, worktrees for parallel work, and why /rewind does not undo what a background review wrote.
The documentation says a plugin runs arbitrary code with your privileges. The five-minute checklist using the tools already shipping in Claude Code.
One of the three stopped being a separate category. The four questions that pick the right mechanism, and the precedence table that flips order between them.
48,000 real turns measured across 67 sessions. Where the money goes, why turn 400 costs three times turn 10, and how much compaction gives back.
Eighteen documented behaviors that degrade in silence. The list is organized by symptom: what you see before you know what caused it.
Three mechanisms make Claude Code look forgetful, and each has its own fix. What compaction keeps, what it drops, and what costs you.
Deny beats ask, which beats allow, and specificity changes nothing. Claude Code's three permission layers and the rules that look protective without protecting.
All three adopted the same open standards and the feature comparison ended in a tie. What still differs is where context lives and who enforces restrictions.
A custom command became a skill. What changes: positional arguments, context injected before the agent sees it, and stacking up to six in one message.
The three installation scopes, the precedence that does not merge fields, and the trap of MCP's local scope, which differs from settings' local.
Motion •
The spec's word is reduce, not remove. Why animation: none !important gets it wrong on both sides, and the substitution table that preserves the design.