Hardening my AI Todo Assistant Against Prompt Injection
TL;DR: I shipped a Bedrock Agent todo chatbot and then found I could read another user's todos via prompt injection. The fix that mattered most: promptSessionAttributes is a hint, not enforcement — re
blogs.houessou.com16 min read