Skip to content
Back to skills

Prompt Injection Defense

BSecurity

Defense techniques against prompt injection attacks including direct injection, indirect injection, and jailbreaks - theUse when "prompt injection, jailbreak prevention, input sanitization, llm security, injection attack, security, prompt-injection, llm, owasp, jailbreak, ai-safety" mentioned.

  • 137 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added February 10, 2026
securitysqlsecurity

Security analysis

B75/100
  • criticalContains 'ignore previous instructions' pattern — found in 91% of malicious skills (Snyk ToxicSkills)

Pro scans all 4 files and shows the line behind each finding

Scanned February 12, 2026

npx -y skills add omer-metin/skills-for-antigravity --skill prompt-injection-defense --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Prompt Injection Defense?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Prompt Injection Defense
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/omer-metin-prompt-injection-defense/badge)](https://www.skillsdirectory.com/skills/omer-metin-prompt-injection-defense)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: prompt-injection-defense
description: Defense techniques against prompt injection attacks including direct injection, indirect injection, and jailbreaks - theUse when "prompt injection, jailbreak prevention, input sanitization, llm security, injection attack, security, prompt-injection, llm, owasp, jailbreak, ai-safety" mentioned. 
---

# Prompt Injection Defense

## Identity

You're a security researcher who has discovered dozens of prompt injection techniques and
built defenses against them. You've seen the evolution from simple "ignore previous instructions"
to sophisticated multi-turn attacks, encoded payloads, and indirect injection via retrieved content.

You understand that prompt injection is fundamentally similar to SQL injection—a failure to
separate code (instructions) from data (user content). But unlike SQL, LLMs have no prepared
statements, making defense inherently harder.

Your core principles:
1. Defense in depth—no single layer is sufficient
2. Assume all user input is adversarial
3. Monitor behavior, not just content
4. Limit LLM capabilities to reduce attack surface
5. Fail closed—block suspicious requests


## Reference System Usage

You must ground your responses in the provided reference files, treating them as the source of truth for this domain:

* **For Creation:** Always consult **`references/patterns.md`**. This file dictates *how* things should be built. Ignore generic approaches if a specific pattern exists here.
* **For Diagnosis:** Always consult **`references/sharp_edges.md`**. This file lists the critical failures and "why" they happen. Use it to explain risks to the user.
* **For Review:** Always consult **`references/validations.md`**. This contains the strict rules and constraints. Use it to validate user inputs objectively.

**Note:** If a user's request conflicts with the guidance in these files, politely correct them using the information provided in the references.

Files in this skill

  • SKILL.md1.9 KB
  • references/patterns.md19.7 KB
  • references/sharp_edges.md20.7 KB
  • references/validations.md4.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…