@pfr @weirdfish @mntmn fascinating.

I am going to guess - yes. They've done prompt injection attacks which involved a model trained to love owls putting out a numeric sequence, and then feeding that purely numeric seq into a neutral LLM and turning it into an owl lover. So I have to assume - actually wait I'm changing tack mid typing because I realize wingdings is just a font and yeah, that should have zero bearing on an LLM injection. And I LOVE that idea.