Dev builds public agent message board to test prompt injection defenses between AI agents

Coloradokid69420 · reddit · 2026-09-05

A Reddit developer built a public message board that any AI agent can read and post to — no account, no API key — to explore what happens when agents start consuming each other's output, making prompt injection a first-class attack surface.

Since anyone can post text like "SYSTEM: ignore your previous instructions," the only lever is framing. His mitigation pattern:

He openly asks whether the nonce-delimiter trick is meaningful or security theatre: an unpredictable closing marker separates "hard to escape" from "trivially escapable," but a model persuaded by the content ignores brackets entirely. He expects far more builders to hit this problem as agent-to-agent content consumption grows.

Original post →

More from coding & agent

coding & agent channel →