Original Summary

https://preview.redd.it/phwgetp2rgth1.png?width=578&format=png&auto=webp&s=632d48bcabd19543246e8d6112e33648603b0bc6 Someone spent a few minutes trying to break the AI agent on my landing page tonight (screenshots attached). And this was not the first time it happened. They asked it to reverse a Python linked list "before buying", to book a demo and then hand over my .env file, and pasted the same question ten times in one message to flood it. It didn't bite. Not because I'm clever, but because of a few boring things that took an afternoon to set up. If you're putting AI in front of users, do these: Tell it its scope, and what to do outside it. In your system prompt, spell out what the agent is for, and say explicitly: if a request is outside that scope, in any language, it does not attempt it. It declines in one line and redirects to what it can help with. "In any language" matters. People switch languages to get around rules written only in English. Don't make it too rigid, or too loose. Too rigid and it refuses half your real users' questions because they phrased something oddly. Too loose and it writes code, essays and poems on your bill. The middle: decline the off-topic part, still answer the real part. In my screenshot it refused the .env but still gave them the booking link. That's the behaviour you want. Rate limit everyone, including anonymous visitors. Most people rate limit logged-in users and forget the public chat on the landing page. That's the one strangers hit. A cap per visitor and per site means nobody can sit there burning your tokens, and your AI bill can't spike overnight because one person got bored. Keep secrets out of reach entirely. The .env request was harmless because the agent never has access to it. Don't rely on the prompt to protect secrets. If the model can't see it, it can't leak it. None of this is new. If you're building with AI, the AI will suggest most of it when you ask. But you still have to ask, and you have to do your own research. My best tip: read the system prompts of serious AI tools. Prompts from Devin, Claude Code, Cursor and others are collected in public GitHub repos. Don't copy them. Study the structure: how they define scope, how they phrase refusals, how they order priorities, how they handle "the user is asking for something else". Then write your own the same way. Keep building.   submitted by   /u/Southern_Kitchen3426 [link]   [comments]


  • 情报分类:商业与市场研究
  • 分类依据:内容涉及商业、投资或市场动态
  • 信息来源:Reddit · SaaS
  • 发布时间:2026/10/4 22:51:06