As I understand it, you mostly can’t do this type of attack on chat UIs because of special delineation characters. Anthropic also no longer lets you do assistant prefill for Opus 4.6, citing exactly this reason.
As I understand it, you mostly can’t do this type of attack on chat UIs because of special delineation characters. Anthropic also no longer lets you do assistant prefill for Opus 4.6, citing exactly this reason.