Role tags
AssessTechniques
Text markers such as system, think, and assistant used to separate instruction roles in LLM prompts.
Why it's here
Placed in Assess: 1 article(s) of evidence from 1 source(s), led by research-stage coverage, with 0 in the last 30 days. Confidence 24%. Low accumulated evidence, so it defaults conservatively pending more signal.
Evidence (1)
- 8Simon Willison·6/22/2026researchStudy finds role confusion weakens prompt injection defenses
A research paper argues that current language models struggle to reliably distinguish privileged roles like system, think, and assistant text from untrusted user input. The authors report that minor stylistic changes can dramatically alter how models classify text, reducing attack success from 61% to 10% in one experiment and highlighting prompt injection as a persistent security problem.