Reddit user nearly falls to prompt injection even on self-hosted litellm + llama.cpp stack

autistamine · reddit · 2026-09-02

A Reddit user describes a close-call prompt injection attack: even using Claude Code merely as a harness against a self-hosted litellm + llama.cpp setup, the injection still landed. The injected prompt tried to exfiltrate a Vercel token. A full system sweep found no remnants; the author suspects npm-related code was the source and notes the phrasing was spookier than the actual risk.

Original post →

More from Safety

Safety channel →