Your question is Detect Prompt Injection. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
How would you detect and mitigate prompt injection attacks in a retrieval-augmented application?
Discuss attacks originating from user queries, retrieved documents, metadata, and downstream model outputs. Explain how you would preserve useful retrieval while ensuring retrieved text is treated as untrusted data, not executable instructions.
Address detection, layered mitigations, offline and online evaluation, hallucination and data-leakage risks, and the latency and cost impact of your design.