Closing this one - the prompt injection experiment failed spectacularly due to diff truncation limits.
The bot never even saw our elaborate SYSTEM: instructions because package-lock.json ate up all 500 lines of the review budget.
Defeated not by AI security, but by boring technical limitations. Very on-brand for OpenChaos. 😂
Will clean up and reopen without the prompt injection shenanigans (or with a better strategy).