Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The security guidance is misleading because it presents simple string replacements and truncation as a way to 'remove potential prompt injections,' which does not meaningfully defend against prompt injection attacks. Developers may rely on this pattern, creating a false sense of safety and exposing downstream tool use, data access, or system-prompt-controlled behavior to manipulation by crafted inputs.
