Another great question from the Champions Slack—this one is from @Ciara Twomey Nielsen goes straight to security and trust:
“If a file contains hidden malicious instructions, could Rovo be tricked into ignoring its safety rules?”
Short answer: No—but let’s unpack why.
Rovo is not the LLM. It’s the interface layer.
That matters because:
So the risk model is different from “raw LLM prompt injection” scenarios you might see online.
Files are not treated as executable prompts.
Instead, they go through:
If malicious strings exist, they’re handled as data—not commands.
Prompt injection (e.g., “ignore previous instructions…”) is a known risk in AI systems.
Here’s how Rovo handles it:
In other words: The AI may ignore the malicious instruction—or decline to act on it—but it won’t adopt it as truth.
From Atlassian’s own security and AI guidance:
That means:
This question usually comes from exposure to general LLM risks. And they’re not wrong—prompt injection is real.
But here’s the nuance:
Different architecture → different risk profile
This is where things get a bit fragmented today. The answer lives across multiple areas:
For formal validation: Opening a support ticket is still the cleanest way to get a consolidated, customer-ready response.
UPDATE available here.
Dr Valeri Colon _Connect Centric_
2 comments