Injection Testing on a Local Support Agent
jokiruiz · reddit · 2026-07-14
The author built a Flask support agent using a local Mistral Small model (via Ollama) to read orders and decide on refunds, specifically testing its resilience to prompt injection.
Results show:
- With a naive prompt, the model accepts forged SYSTEM instructions and directly approves unwarranted refunds.
- After adding a defensive prompt, the same model on the same machine starts rejecting attacks and can cite policies to explain why.
- The author notes the difference is literally just 5 lines of text.
Additional observations:
- Ollama's format: json solves most JSON output instability issues.
- Stronger LLMs won't necessarily save a bad prompt; the author mentions Sonnet resists injection but fails on a poorly defined business rule.
- He is looking for better fully local testing solutions and asked if there are better tools than promptfoo.
More from coding & agent
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11