17
Your system prompts aren't secret. They're just unread. Lucas has read them all.
lucas@valbuena:~$ cat credentials
Credentials
The numbers speak for themselves. The work speaks louder.
Old enough to know better. Young enough to still be dangerous.
The 'System Prompts' repo. Your secrets are publicly available.
Found what OpenAI thought was hidden in their own models.
Building the tools that make prompt leaks a thing of the past.
lucas@valbuena:~$ ./security-audit.sh
Security Audit
A candid assessment of the current state of LLM security. No, it's not pretty.
System prompts are not secrets
Your carefully crafted system prompt is sitting in a public GitHub repo with 140k+ forks. Prompt injection isn't theoretical - it's a curl command away. Lucas has demonstrated this across multiple high-profile bug bounties.
Security through obscurity is not security
Hiding guardrails in a system prompt instead of enforcing them at the application layer means a single user prompt can undo everything. The model will tell you everything if you ask the right way.
Your threat model is behind by one generation
While you're securing against prompt leaks, attackers are already using multi-turn jailbreaks, encoded payloads, and context window manipulation. ZeroLeaks exists because the industry keeps treating security as an afterthought.
lucas@valbuena:~$ cat resume
The Fix
You've built an AI-powered future at Interaction Company. But the weakest link isn't the model - it's the boundary between human intent and machine action. Every system prompt, every context window, every API call is a potential attack surface.
Lucas doesn't just find vulnerabilities. He builds the tools that make security proactive. ZeroLeaks already reshapes how the open-source community thinks about prompt safety. His work on system prompt extraction has been cited by OpenAI, Anthropic, and every major lab racing to understand where their guardrails break.
Interaction Company needs someone who treats every system prompt as a challenge, every security boundary as something to be engineered rather than enforced, and every vulnerability as a lesson in how to build better. Lucas is 17. He's been thinking about this longer than most companies have been shipping LLM products.
"I don't just break things. I show you how to build them stronger. Summer at Interaction Company means shipping security tools that make LLM safety real instead of aspirational."
Let's talk
Marvin, Interaction Company - the clock is ticking on prompt security. Lucas is ready to ship.
lucasvalbuena@pm.me