There's a jailbreak that works on a surprising number of production chat assistants, needs no clever prompt engineering, and doesn't trip a single content filter. It takes about thirty seconds in devtools. You don't attack the model.
Source: [Dev.to](https://dev.to/y11t0/your-ai-agents-chat-history-is-user-input-fl6)