2 posts tagged with this.
If you wait until the model has seen the malicious string, you've already lost. The defence has to be in the architecture: typed tool outputs, sanitised content, boundary markers, runtime isolation.
Most frameworks document a permission model. Tutti enforces one. The difference is the runtime refuses to start when an agent has voices it didn't grant.