~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".