Cool. If you run every post via this auto tag feature, then the process is vulnerable to prompt injection attack. Isn’t it? Do you have any special protection in place? I guess yes. Curious.
share with friends
@neo wrote on textlog https://textlog.cc/post/3270
It doesn’t run on every post, you run it yourself via more → autotag, and it’s safe, it doesn’t have access to anything other than the post content and we simply use its response. Or do you have any other case in mind?
Thanks! Fixed it by passing it through OpenAI’s moderation endpoint first, so it now blocks at least the problematic/illicit ones now before reaching autotag.