We should handle LLMs as insider threat instead of typical input parsing problem and we get much better.
All text input is privileged code basically. There is no delimiting possible.