How Not to Detect Prompt Injections with an LLM