An RSS reader with memory
The reader that remembers
what you thought.
Every feed you follow arrives in one inbox, with a summary of what each piece argues before you give it half an hour. Your rating, your tags and what you wrote about it stay in a library you can still search years from now.
bring your opml with you
Inbox
42 unreadEverything unread, newest first
Everything I know about prompt injection, two years on
The attack still has no fix. Here are the mitigations that help, and why every agent vendor keeps rediscovering the same wall.
- 01Prompt injection is unsolved: any system that concatenates untrusted text with its own instructions inherits the vulnerability, and no amount of prompting removes it.
- 02Guardrail models catch the obvious attacks and miss the interesting ones. Treat them as spam filters, not as a security boundary.
- 03The dual-LLM pattern, where a quarantined model never touches tools, is the only mitigation with a real argument behind it.
- 04Anything holding both private data and an outbound channel is exploitable. Design the blast radius, not the prompt.
Two years ago I wrote that we had no fix for prompt injection. I would like to report that this has changed. It has not.
What has changed is the shape of the industry around it. Every serious vendor now ships an agent that reads untrusted text and then acts on it — browsing, filing tickets, sending mail — and every one of them has independently arrived at the same three mitigations, in the same order, usually after the same incident.
The problem
You read four hundred things last year.
Name three.
The reading was never the hard part. Hermes is the reader that keeps the other half: what you made of it, in your own words, still there in five years.
How it works
The whole loop is five moves long.
Everything in Hermes exists to keep it short.
- 01
Subscribe
Paste a feed URL, or import the OPML from your last reader. Folders come across with it.
- 02
Triage
New items land in the inbox. Skim the list, open what looks worth it, archive the rest without leaving the keyboard.
- 03
Read
A serious reading column: Newsreader serif, a sane measure, and the TL;DR sitting on top.
- 04
Take
Rate it one to five, tag it, and write down what you thought while it is still fresh.
- 05
Compound
The library grows. Months later, "what did I make of that Postgres piece" is one search away.
01 — Take
Say it while you still mean it.
One keystroke opens the drawer: five stars, whatever tags you file it under, and a box for the sentence you would otherwise have said out loud and lost. It takes about a minute.
Everything I know about prompt injection, two years on
The attack that still has no fix, the mitigations that actually help, and why every agent vendor keeps rediscovering the same wall.
My take
Everything I know about prompt injection, two years on02 — Compound
Search what you thought, not just what you read.
Every take is filed the moment you write it, and the Library searches across all of them at once: words, tags and stars together. A year in, that is a few hundred articles you can look things up in.
Everything you’ve read, tagged, and saved.
“The clearest statement yet of why this is architectural. Quarantine the model that reads untrusted text, and never give it a tool.”
“Finally the packfile explanation that stuck. I have read six of these and this is the one I will send people.”
“The health check passing for the wrong reason is the detail I keep thinking about. We have three of those.”
03 — Discuss
Somebody already read the comments.
When something you follow reaches the Hacker News front page, Hermes attaches the argument to the article: what the thread agrees on and what it is fighting about. The comments, without the tab.
…and every one of them has independently arrived at the same three mitigations, in the same order, usually after the same incident.
On Hacker News
412 218Open thread →Broad agreement that the piece is right about the mechanism and too gentle about the industry: several commenters argue the real failure is architectural, not linguistic, and that any agent holding private data plus an outbound tool is exploitable by construction. A smaller thread pushes back that the dual-LLM pattern is unshippable in practice because it removes the capability users are paying for. Nobody in the top fifty comments defends guardrail classifiers as a boundary.
The framing people keep missing: this is not a filtering problem, it is a capability problem. If the model can both read attacker text and reach a tool that leaves the machine, you have already lost, and the prompt is a detail.
I have started treating every guardrail claim the way I treat "our crypto is unbreakable". Show me the boundary, not the benchmark.
The lens
Hacker News, in the same window.
Front, best, ask, show and new, with the thread on the right and a marker on every story you already follow. Press h from anywhere.
Everything I know about prompt injection, two years on
simonwillison.net
Also in the box
Colophon.
- Summaries
- Three to five bullets above every article, drawn from the full text. Enough to tell whether it is worth the next half hour.
- Keys
- 1–5 for the views, h for Hacker News, s to star, l to save, o for your take, ⌘K for the rest. The mouse is optional throughout.
- Views
- Inbox, Today, Read Later, Starred and Library, each on its own number key.
- Folders
- However you had them filed in your last reader. They come across with the import.
- Import
- OPML in and OPML out. The import returns immediately; eighty subscriptions fill in behind it over the next few minutes, while you read.
- Themes
- Light paper, warm dark, and a sepia for long evenings. The reading column is typeset for all three.
- Type
- Newsreader for prose, Geist for the interface, Geist Mono for anything you might transcribe.
- Privacy
- Ratings, tags and takes belong to your account. No public profile, no shared timeline, nothing to follow.
- Cost
- Nothing. There is no paid tier and no plan to add one.
FAQ
The usual questions.
Can I bring my subscriptions with me?
Yes. Export the OPML from whatever you read in now and drop it into Hermes. Feeds and folders both come across. The import returns immediately and the new feeds fill in behind it.
How do I get an account?
Registration asks for an invite code, and every member has one to pass along. With a code in hand the account takes about a minute. Sign-in also accepts single sign-on if your organisation has it set up.
What exactly does the AI do?
Two things, both before you read. Every article gets a three-to-five bullet TL;DR drawn from the full text, and articles that reached the Hacker News front page get a summary of what that thread is arguing. It never rewrites the piece.
Can I read without any of that?
Yes. The summaries sit in a card above the article, and the Hacker News lens is a view you visit rather than a feed pushed at you. Scroll past both and Hermes is a fast keyboard-driven reader.
Who can see my ratings and notes?
Nobody. Ratings, tags and takes are private to your account. There is no public profile and no shared timeline; the Library is a record you keep for yourself.
Is it really keyboard-first?
The number keys 1–5 move between Inbox, Today, Read Later, Starred and Library. h opens the Hacker News lens, s stars, l saves for later, o opens your take, and ⌘K reaches everything else. Reaching for the mouse is optional throughout.
What does it cost?
Nothing. There is no paid tier and no plan to add one.
The next thing you read
is worth keeping.
Bring your feeds over, read one article properly, and write down what you made of it. That is the whole product. It pays off the second time you search.
sign-up takes an invite code