“To test this, we attacked a mock victim’s Cloud Function and sent a prompt injection input into ... “The attack was executed ...