mirror of
https://github.com/langchain-ai/docs.git
synced 2026-07-21 03:45:28 -04:00
[GH-ISSUE #2765] RAG model in tutorial outputs JSON without thoughts instead of saying 'I don't know' #2673
Closed
opened 2026-06-05 17:24:48 -04:00 by yindo
·
15 comments
No Branch/Tag Specified
main
prod
preview-docsca-1784605966-0deeb00
docs/capitalize-interrupt-cancel-run-section
open-swe/gateway-dotenv-tab
preview-docsfi-1784603715-50e39c0
docs/fix-permissions-card-missing-icon
preview-docsfi-1784603391-03d7054
preview-docsmd-1784603382-5e99033
docs/mda-dev-deploy-code-blocks-in-diagram
preview-docsmd-1784603179-6ed1cd4
preview-docsca-1784602648-150b043
preview-docsfi-1784602498-d1c6323
docs/fix-self-referencing-quickstart-card-next-steps
open-swe/clarify-trace-retention
preview-docsfi-1784584027-bbf5868
preview-eliver-1784583968-8acf1be
docs/fix-assistantsclient-create-js-reference
eli-verdun/docs/fix-curl-capitalization
preview-docsfi-1784583401-78654de
docs/fix-same-thread-agents-to-assistants
preview-docsfi-1784583263-c7946a4
preview-docsfi-1784582900-9a6d05c
docs/fix-assistants-duplicate-sections
preview-mdrxyd-1784582452-550d6f7
mdrxy/docs/approval-modes
preview-cbdocs-1784580064-7f7e9d4
cb/docs-mda-memory
preview-docsde-1784577418-f712cd8
preview-dashbo-1784577253-dbbcb67
docs/deepagents-mcp-project-approvals
dashboard-v2-update
preview-dashbo-1784575921-bae3eac
preview-docsot-1784575388-97ada39
docs/otel-gateway-inclusive-oss-language
preview-docsot-1784574768-01c9245
preview-docsre-1784572283-f30bfe2
docs/replica-primary-feedback-compute-run-id
preview-dashbo-1784570114-89ca06e
preview-kiewan-1784569091-0de567f
kiewan/adapt-migration-guide-to-new-sdks
preview-kiewan-1784567881-7533374
preview-kiewan-1784565396-81e0715
preview-kiewan-1784564323-9f777da
preview-docsre-1784559147-fb47b00
docs/replace-dcode-section-with-note-on-dynamic-subagents
preview-docsre-1784559035-2c4def7
preview-docsup-1784558521-f5a6823
docs/update-dynamic-subagents-card-link
docs/add-reference-langchain-mcp
preview-fjmorr-1784514371-cc39e6e
fjmorris/DOC-1379
chore/update-package-downloads-20260720-002310
chore/refresh-langsmith-openapi-20260719-103308
preview-cbmdac-1784404575-9ef230d
cb/mda-channel-docs
chore/refresh-langsmith-openapi-20260718-103212
preview-docsde-1784335089-f17e3b2
docs/deepagents-code-hooks-claude-compatible
preview-docsde-1784334655-403df66
preview-docsde-1784332878-8b764e2
preview-cbiden-1784320915-d424d53
cb/identity-refinement
preview-cbiden-1784319986-74f7164
preview-dashbo-1784318717-1fa5f94
preview-cbdocs-1784316992-3f2f380
preview-cbiden-1784316929-256b3f2
preview-cbdocs-1784312750-b6243cc
preview-docsfi-1784308120-df1be5b
docs/fix-saml-sso-checkbox-name
marthajanicki-patch-2
preview-cbdocs-1784230442-77c063c
cb/docs-mda-evals
preview-cbdocs-1784230282-5e59486
preview-update-1784195084-60ad7d5
chore/sync-deepagents-signatures-20260716-094439
preview-cbdocs-1784159788-7d0d491
preview-cbdocs-1784159622-57bc312
preview-cbdocs-1784159497-b2e8101
preview-cbdocs-1784159267-4094d75
preview-cbdocs-1784159006-d39833c
preview-cbdocs-1784158901-6000dd6
preview-rafidf-1784156729-8f496fa
rafid/fleet-manual-oauth-providers
preview-depend-1784151761-c3979d2
chore/refresh-langsmith-openapi-20260715-103709
preview-update-1784108410-570f695
preview-update-1784048844-877aa62
preview-banner-1784042257-24da6e1
preview-mdb483-1784027663-2a49cbf
mdb-4834
preview-integr-1784021393-eeb8347
integrations-page
preview-integr-1784020802-1e7e080
preview-integr-1784018158-000ff5b
preview-integr-1784017352-04ce8b8
ramon/llm-gateway-fallback-docs
chore/refresh-langsmith-openapi-20260713-110557
chore/update-package-downloads-20260713-002220
chore/refresh-langsmith-openapi-20260712-103308
chore/refresh-langsmith-openapi-20260711-102949
preview-daniel-1783733921-24756c7
daniel/self-hosted-sandboxes-docs
preview-sineha-1783732909-9486b1c
sineha/trace-retention-docs
preview-sineha-1783732753-7a18114
preview-sineha-1783728458-520e8e7
preview-sineha-1783728033-164756f
preview-sineha-1783727914-e35b75c
preview-sineha-1783727767-4cc292c
preview-sineha-1783727666-55f51d4
preview-sineha-1783727546-63587f3
preview-sineha-1783727386-d139cc2
preview-sineha-1783727055-f63aa65
preview-daniel-1783723881-3c687af
preview-daniel-1783723436-063ede1
preview-daniel-1783723018-aac95f8
docs/smithdb-runs-retrieve-not-found
open-swe/gateway-env-config
chore/refresh-langsmith-openapi-20260710-110457
preview-daniel-1783668723-cf21e1a
preview-daniel-1783612045-e7d9594
open-swe/ent-641-invite-rate-limits
preview-daniel-1783602851-ae08e1a
preview-ENT122-1783590571-e3e66b2
ENT-1224-support-idp-migration-custom-oidc-docs
preview-ENT122-1783590043-8a20c20
preview-daniel-1783588750-d5f5910
preview-daniel-1783587722-0410fe3
preview-daniel-1783582715-ba8f300
preview-daniel-1783581241-1474c5a
preview-ENT887-1783568664-ab50373
ENT-887-workspaces-manage-keys-docs
preview-ENT887-1783567918-50fe5cc
preview-ENT887-1783567719-bffb3ad
mdrxy/docs/deepagents-code-uninstall
open-swe/document-issues-agent-categories
preview-daniel-1783525614-ead4256
preview-daniel-1783522155-e43e418
preview-daniel-1783521815-d1e11f7
preview-daniel-1783521441-fa8883d
preview-daniel-1783521012-dcf6621
preview-daniel-1783520818-de550f3
preview-daniel-1783520169-f65238f
preview-daniel-1783497107-25e850a
preview-docsja-1783484944-f86c4f0
docs/java-evaluate-function
preview-docsja-1783470579-e03df1a
preview-docsja-1783470257-3ea8c2c
preview-docsja-1783464834-ff12d22
preview-docsja-1783458563-d32e7e5
preview-docsja-1783458425-a4ccf93
changelog-bot-update-0b01bd83
docs/remove-langgraph-cloud-license-key-prerequisite
marthajanicki-patch-1-1
marthajanicki-patch-1
chore/sync-deepagents-signatures-20260707-101152
preview-ENT887-1783397151-af64c63
preview-docsja-1783351721-295b97a
docs/add-otel-resource-attributes-paragraph
chore/refresh-langsmith-openapi-20260706-113642
chore/update-package-downloads-20260706-002551
chore/sync-deepagents-signatures-20260703-100314
changelog-bot-update-e439a118
docs/add-llm-gateway-pages-to-nav
naomi/doc-1157-improve-discoverability-of-deep-agents-deepagents-code-docs
open-swe/backend-agent-bootstrap-v15-docs
lauren/weekly-changelog-2026-06-28
quentin/api-rate-limits-docs
chore/refresh-langsmith-openapi-20260629-114709
preview-docsdy-1782657543-018f79d
fjmorris/DOC-1303
remove-mda-api-docs
open-swe/harbor-python-docs
open-swe/remove-sandbox-registry-creds
preview-benrev-1782332859-4c2fc83
open-swe/dcode-langsmith-project-docs
open-swe/cursor-integration-doc
mdrxy/dcode-eu
open-swe/codex-openai-key-coexistence
docs/sandboxes-environment-availability-ga
chore/update-package-downloads-20260622-003215
preview-readdc-1781897196-fb126f6
revert-commit
preview-cbbump-1781709559-ef2b3a8
open-swe/openrouter-tool-cache-control
mukil/remote-mcp-api-key-docs
docs/fix-kubernetes-initial-org-admin-email-placement
preview-davidp-1781625753-550b737
david/preview-build-docs
docs/fix-sandbox-nav-active-state
ff2
docs/redirect-langsmith-home-to-monitor
docs/add-online-evaluators-to-monitor-observe
preview-davidp-1781542321-9a249fa
docs/fix-agent-lifecycle-404
chore/refresh-langsmith-openapi-20260615-120708
docs/move-configure-checkpointer-to-server-customization
docs/fix-stray-python-subagents-streaming
preview-cbbump-1781294718-0c1589f
preview-docssk-1781190617-4dc61d8
docs/skills-availability-permissions
update-openapi-spec-v0.10.0
changelog-bot-update-597bc00f
mdrxy/dcode-config
preview-mdrxym-1781066746-d700eed
open-swe/trace-pi-coding-agent
open-swe/sandbox-harbor-docs
update-tool-return-code
preview-subage-1780900407-f67d2f0
subagent-img
colifran/interp-lib-and-swarm
colifran/interp-libs
preview-ENT489-1780617325-b81bddf
ENT-489-personal-org-trace-limits-docs
docs/fix-how-capitalization
preview-jdroge-1780516422-c2bf1e2
jdrogers940-patch-1
open-swe/deepagents-filesystem-ls-docs
preview-davidf-1780410500-f0e8b21
docs/add-hitl-when-predicate
preview-warnin-1780335965-8976c65
warnings-all-int
open-swe/doc-1181-llm-auth-proxy-note
open-swe/harbor-langsmith-guide
update-openapi-spec-v0.8.7
preview-bestpr-1780000780-6a2ab16
best-practice-traces
langsmith-fleet-rename-docs
preview-bestpr-1779997959-dbb4014
changelog-bot-update-466aa7a4
preview-fixsel-1779841279-4b33a7e
fix/context-hub-sdk-docs
hunter/module-metadata
chore/refresh-langsmith-openapi-20260525-112945
chore/update-package-downloads-20260525-002649
preview-docsus-1779492549-fbb64a4
docs/use-langsmith-sandboxes-in-guides
vic/fix-interrupt-mda-typo
changelog-bot-update-4d1ec0bc
open-swe/rename-deep-agents-code-sidebar
sr/custom-agents-advanced
marthajanicki-setUpCodingAgents-codingAgentAuth
open-swe/deepagents-code-js-interpreter
preview-sectio-1779306767-b45259f
mukil/sandbox-permissions-doc
docs/supervisor-migration-guide
open-swe/fix-graph-defaults-heading
open-swe/add-eager-tools-middleware
open-swe/engine-webhooks-slack-example
open-swe/changelog-drop-patch
open-swe/sync-deepagents-models
docs/test-pr-automation
docs/test-pr-automation-2
preview-mdrxyf-1778891062-175d4da
open-swe/deep-agents-context-multimodal
changelog-bot-update-b940039b
open-swe/doc-1120-comprehend-pii
preview-nhuses-1778700384-2b3c094
nh/usestream-frontend-docs
preview-nhuses-1778699885-70d5ae2
open-swe/fault-tolerance-set-node-defaults
fjmorris/DOC-1069
naomi/doc-1039-more-heavy-xlinking-between-this-and-this
open-swe/docs-set-node-defaults
open-swe/docs-context-hub-backend
open-swe/sandbox-service-url-refresh-doc
mukil/deprecate-old-langsmith-mcp
long/delta-chekpointer-guide
chore/sync-deepagents-signatures-20260507-095509
changelog-bot-update-a3160b68
chore/sync-deepagents-signatures-20260506-095242
chore/sync-deepagents-signatures-20260505-094229
open-swe/9d01c6ec-9a1e-f7c2-64a6-849b03777462
chore/sync-deepagents-signatures-20260504-095216
chore/update-package-downloads-20260504-002134
open-swe/2c388642-30ed-92d5-12de-4b36b9a52dcf
open-swe/6f8751a7-2317-6c86-e2d8-1b346608b6fc
open-swe/964438d8-0063-5620-a68b-183ff99019bb
chore/sync-deepagents-signatures-20260430-094651
docs/add-model-config-api
mdrxy/da-cli-fsajk
open-swe/950a4654-e73b-c3eb-568f-af8a40b02675
chore/sync-deepagents-signatures-20260429-094651
open-swe/304c9ecc-7d11-6c64-2cfb-9410320726a6
update-constraints-v0.8.2
preview-shrn-1777307722-4ee2cf3
chore/update-package-downloads-20260427-001739
preview-gpt5-1777059718-47af0d3
preview-wfhbgj-1777054999-5e4de3a
open-swe/4df2a389-91bf-200d-3f68-6161a6e64b71
preview-immanu-1776816584-197cf7a
immanuel-ai-171
preview-immanu-1776815725-f709483
immanuel-ai-170
mdrxy/subgraph-cr-agent
preview-immanu-1776807735-90ee807
immanuel-ai-168
open-swe/9beb3610-d672-a00c-08e0-a3e088f1e060
fjmorris/DOC-1010
docs/fleet-github-app-self-hosted
preview-cost-1776193380-7cd750c
preview-cost-1776190401-8e23c22
preview-cost-1776190025-cb56175
open-swe/8d7b0026-5bc3-e1cf-bdfe-7b24d78c54d2
preview-vicgra-1775865328-22e64a9
vic/graph-breaking-changes
preview-htmlte-1775837771-8253f4a
htmltest
preview-htmlte-1775824163-d8aa286
preview-htmlte-1775824066-66873a2
fjmorris/DOC-957
cb/document-streaming-protocol
preview-wfhenv-1775681775-f63fd7e
wfh/env_vars
preview-htmlte-1775656973-0d8dbf5
update-skills-page
sr/little-mem-patch
preview-jacobo-1775559973-01469a1
preview-linkst-1775509693-88c55b4
preview-sraddi-1775494500-2b9e759
preview-wfhcac-1775482911-620a838
wfh/caching_docs
preview-wfhenv-1775241977-1fe3764
preview-wfhenv-1775241693-e06fab8
preview-jakein-1775234281-4d683b4
jake-insights-cli-docs
preview-wfhenv-1775232062-60e7a90
preview-wfhcac-1775165461-30a695b
preview-wfhcac-1775090211-3eba851
open-swe/b6691feb-f3cb-78b3-5d08-aa38f4a0d723
hunter/configurable-api-keys
preview-cbclc3-1774894224-cf8de59
colifran/backend-refactor
open-swe/6ebd0fb3-6771-390a-213d-7f7ca025e7c8
preview-fleetn-1774291139-aedb23d
preview-wfhcac-1774042849-4552e68
eugene/docs-update
cc/deepagents_backends_v0-5
wfh/mongo_cleanup
feat/crewai-langsmith-crewai-package
preview-reorga-1773853277-3e4de97
preview-reorga-1773851634-c29d7d3
preview-reorga-1773849788-3f9cc12
preview-simpli-1773745162-aa10ba5
simplified-left-hand-nav
wfh/disambiguate
preview-merged-1773674134-a8ee819
merge-deepagents-langchain-manual
preview-merged-1773673439-f47cb10
preview-merged-1773673244-b9c7618
preview-merged-1773671975-82b0e66
preview-merged-1773671637-4045d84
wfh/lsd_mongo_all_three
preview-wfhupd-1773416505-c64faa9
preview-parker-1773416333-c3fa44d
preview-mermcs-1773349448-32de48d
preview-fixnew-1773346721-757befb
hunter/repl-updates
mdrxy/oauth
preview-cbchat-1773214433-b6b3b5d
preview-wfhnit-1773168834-68f5884
cc/openai_tool_search
open-swe/b1dc3811-7695-a6d3-0b98-c0b4232ab7b5
hunter/google-embeddings
preview-ccopen-1773097524-a69399c
cb/chat-langchain-integration
preview-wfhupd-1772850372-e640909
open-swe/f13c817d-6db4-8632-05aa-1388189d105e
palash/add-langsmith-cli
palash/add-langsmith-skilsl
preview-layout-1772484041-c236b7b
preview-font2-1772479844-74361b8
preview-fontfi-1772478541-75d4f7b
preview-bulkex-1772477080-6c9be93
preview-redire-1772471288-be16ed8
preview-ffrebr-1772469371-1d3f65d
wfh/auth_docs_updates
dependabot/npm_and_yarn/reference/javascript/npm_and_yarn-10729c40e0
preview-ericdo-1771862591-74fcf18
preview-ericdo-1771862572-2607e04
preview-wfhcus-1771536914-b32b47d
preview-ccpyda-1771512208-8c0203e
preview-ccoaia-1771425169-3966492
preview-htmlte-1771358383-35b71d3
broken-link-htmltest
open-swe/8c3830fe-8ac7-bb6e-369e-0cb56ded87ec
mintlify/find-personal-previews-51934
preview-ericda-1770934356-1e3f78c
preview-standa-1770924224-dc00eb6
standardize-beta-tag
preview-parker-1770921354-f58b62d
preview-standa-1770920789-2552475
revert-2497-docs/gemini-structured-output-fix
docs/update-trace-query-syntax-filters
hunter/snippets-command
No results found.
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: langchain-ai/docs#2673
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @anupamck on GitHub (Aug 27, 2025).
Original GitHub issue: https://github.com/langchain-ai/docs/issues/2765
Checked other resources
Example Code
I use the RAG tutorial code, as specified here.
To test this model, I pass the following query:
The reproducible code example can be found here in this Jupyter notebook.
Error Message and Stack Trace (if applicable)
No response
Description
I have set up the RAG QA model with a clear instruction to say "I don't know", if a particular question cannot be answered using its context.
When I ask the question "What is the taste of an orange?", I expect the response "I don't know".
Instead, I receive the following response:
Debugging hint
To debug this, I changed the code in the 'generate' step of the graph to
return {"answer": response}fromreturn {"answer": response.content}, so that I can read the whole response object. I then received the following output:Here, the
contentkey of the object does have the expected text. Once I saw this and reverted the code back toreturn {"answer": response.content}, I actually received the expected response.System Info
System Information
Package Information
Optional packages not installed
Other Dependencies
@Tik1993 commented on GitHub (Sep 1, 2025):
Are you using
prompt = hub.pull("rlm/rag-prompt", api_url="https://api.smith.langchain.com")to retrieve the prompt?I believe the issue comes from the prompt itself, because when I explicitly create the prompt in my code and apply it to the
generatenode, the issue no longer occurs.@anupamck commented on GitHub (Sep 2, 2025):
@Tik1993 - Thank you. I did as you are told, and found that even if I include the prompt in the code (rather than pulling it), the problem still occurs:
I am using
Note that the bug where the LLM's "thoughts" are output is limited to this specific question: "What is the taste of an orange?". When I ask "What is orange?", like you have, I receive the following reply:
This is also buggy, since the expected response is, "I don't know", but not in the same manner (with thoughts output as a JSON).
So merely localising the prompt isn't solving the problem. However, you may still be onto something. I noticed that when I invoked the code as you had suggested...
...and asked your question, "What is orange?", I get "I don't understand" as a response instead of the buggy response
Orange is a color that is a mix of red and yellow..., which is progress.Nevertheless, even with your suggested changes, when I ask my specifically buggy question,
What is the taste of an orange?, the buggy behaviour by which a thoughts JSON is output is still reproducible.I suspect that some abstractions used in the
generatefunctions are behind this bug.@Tik1993 commented on GitHub (Sep 2, 2025):
Hi @anupamck, the reason getting "I don't understand" as a response is because I updated the prompt to say "If you don't know the answer, just say that you don't understand," instead of "you don't know." That was my mistake, and I’ve updated my previous reply.
In your code, would you mind showing how you invoke the graph?
@anupamck commented on GitHub (Sep 2, 2025):
By simply using
My entire code can be found here in this Jupyter notebook
@luke396 commented on GitHub (Sep 11, 2025):
Some really interest things:
The orange answer format is not just simple text, but a json. The reason is that we accidentally provided some response format rules in the context of the rag, which caused the answer to change.
@Daniyal0100101 commented on GitHub (Sep 11, 2025):
Excellent analysis @luke396! This is a classic example of prompt contamination in RAG systems - a critical issue that many developers encounter when working with diverse document sources.
Root Cause Analysis
The problem occurs because the RAG retrieval is pulling in documents that contain response format instructions (
"You should only respond in JSON format..."). When this gets included in the context, it overrides the explicit "I don't know" instruction in your system prompt. The LLM is essentially receiving conflicting instructions:The context instruction wins because it appears more recently in the prompt.
Immediate Solutions
1. Content Filtering During Indexing:
2. Strengthen System Prompt:
3. Post-Processing Filter:
This is a valuable learning case for the community - I've seen similar issues when RAG systems index documentation that contains prompt engineering examples or API response formats. The key is treating this as a prompt security issue where you need to sanitize both input documents and strengthen your system instructions.
Would be happy to contribute a documentation update or example showing best practices for handling prompt contamination in RAG systems!
P.S. - I'm working on a similar prompt optimization tool (prompt-optimizer) that uses Gemini API. Would love to collaborate on making LangChain's RAG tutorials more robust against these edge cases.
@luke396 commented on GitHub (Sep 11, 2025):
Hi, @Daniyal0100101. Just a quick thought: adding another model to check the results of the model with context might also be another way to enhance the robustness of RAG results.
@Daniyal0100101 commented on GitHub (Sep 12, 2025):
@luke396 You're right using another one to scan the output first is a great idea, but it also makes the system even more complex and by multiples API calls can be costly. So first try to refine your approach with the model first. If needed add another layer of verification.
@anupamck commented on GitHub (Sep 12, 2025):
Wow - this is some fantastic analysis. When I posted this bug, I didn't expect to learn about such a fundamental security hole in RAG models. Thank you, @luke396 and @Daniyal0100101 for the insights!
The solutions you propose above, @Daniyal0100101, will work, but I see them as workarounds. I find a more elegant solution to be escaping prompts from retrieved contexts in RAG models (much like how escaping works in SQL queries to project against injection attacks). Do you know of such a feature? If not, I am happy to submit a request for the same.
@aaron-seq commented on GitHub (Oct 24, 2025):
This is a brilliant analysis by @luke396 and @Daniyal0100101! This issue perfectly illustrates a critical security pattern in RAG systems that deserves more visibility.
This is a Prompt Injection Security Issue, Not Just a Bug
What you've uncovered here is a textbook example of indirect prompt injection in RAG systems. This has serious security implications beyond just getting weird JSON responses.
Documentation Enhancement Proposal
I'd like to propose adding a "RAG Security Best Practices" section to the LangChain documentation that covers:
1. Prompt Injection Prevention
2. Context Isolation Techniques
3. Response Validation
Proposed Tutorial Updates
Current RAG Tutorial Issues:
Suggested Additions:
Implementation Plan
Would the team be interested in me creating:
This issue reveals a fundamental gap in RAG security education. The solution isn't just fixing this specific case, but educating developers about a whole class of security vulnerabilities.
@anupamck Your SQL injection analogy is spot on - we need "prepared statements" for RAG systems!
I'm actively working on secure AI patterns and would love to contribute this knowledge back to the LangChain community. This could prevent many developers from unknowingly creating vulnerable RAG applications.
@madhavmadupu commented on GitHub (Jan 15, 2026):
Proposed Solution: Context Isolation and Defensive Prompting
The root cause is that the LLM treats the instructions found inside the retrieved context (e.g.,
"You should only respond in JSON format...") as new system instructions that override your original prompt.To solve this, I recommend a three-layered approach: Demarcation, Explicit Instruction, and Content Sanitization.
1. Use XML Tags for Context Demarcation
LLMs (especially GPT-4o and Claude) are trained to recognize XML tags as structural boundaries. By wrapping the context, you clearly separate "Data" from "Instructions."
2. Strengthen the System Prompt (Defensive Prompting)
Explicitly tell the model to treat the context as raw data and to ignore any commands found within it.
Updated Prompt Example:
3. Sanitize Context during Retrieval (Pre-processing)
If you are indexing documents that you know contain prompt engineering examples (like AI research papers or documentation), you should strip out common injection phrases during the
generatestep.Why this works:
This pattern is effectively the "Prepared Statement" (SQL-style) equivalent for RAG systems.
@anupamck commented on GitHub (Feb 1, 2026):
While I appreciate the suggestions in this thread, I don't see them as equivalent to SQL Prepared Statelements. I see that the approach here involves prompt hardening and prompt sanitization by removing common attack patterns. They certainly increase security, but aren't foolproof. What if a 'hardened' prompt encounters and even 'harder' instruction statement? Also, sanitization fails if the framing of the attack can be done in a manner that finds a way around the phrases we select to exclude.
What is the fundamental issue here? My understanding is that the system prompt and the retrieved context land in the same context window of the LLM. Once they are in the same context window, they could contradict each other and create security holes.
I am not sure if LLM architecture allows this, but what if we had two different windows: one purely for instructions and another purely for data? This way, any instructions within retrieved context will be treated purely as data.
@Daniyal0100101 commented on GitHub (Feb 1, 2026):
Hi @anupamck,
Thanks for the thoughtful reply—you're absolutely right that hardening and sanitization devolve into a cat-and-mouse game. My comparison to SQL Prepared Statements was imprecise; I was looking for an equivalent architectural guarantee, not just a surface-level similarity.
Your diagnosis of the fundamental issue (system instructions and retrieved data sharing the same context window) hits the nail on the head. This is exactly why prompt injection remains unsolved—we're asking the model to distinguish between "code" (instructions) and "data" (retrieved context) when both are just tokens in the same stream.
Regarding your proposal for dual context windows (instruction window vs. data window):
Conceptually, this aligns with what Anthropic proposed in their Instruction Hierarchy research—essentially hard-coding privilege boundaries so that "data" tokens cannot override "instruction" tokens regardless of their content. If LLM architectures supported true separation (akin to Harvard architecture vs. Von Neumann), injection attacks would indeed become structurally impossible.
Pragmatically, since we can't modify the underlying model architecture today, do you see any viable intermediate patterns that approximate this separation within LangChain's current abstractions? For example:
Documentation angle: Given that perfect prevention isn't currently possible, would the maintainers be open to a PR that adds a "Security Limitations" section to the RAG tutorials? This would explicitly state that standard RAG chains share a context window and are vulnerable to injection, rather than implying hardening is sufficient.
Essentially, I'm trying to determine: is the team's position that users should accept this architectural limitation as inherent to current LLMs, or is there appetite for LangChain to pioneer abstraction-level mitigations (like your two-window proposal) even if they require creative prompt engineering or multi-stage chains?
Happy to prototype something if there's interest in exploring further.
@ManasVardhan commented on GitHub (Feb 19, 2026):
I'll investigate and fix this issue with the RAG tutorial output format.
@ManasVardhan commented on GitHub (Feb 19, 2026):
Investigation Summary
After investigating this issue, here are my findings:
The tutorial has been completely rewritten
The RAG tutorial at https://python.langchain.com/docs/tutorials/rag/ has been significantly updated since this issue was filed. The old LangGraph-based approach with
graph.invoke()and thegeneratenode (usingresponse.content) has been replaced with acreate_agent-based approach using tools and middleware. The code referenced in this issue no longer exists in the current tutorial.Root cause analysis
Based on the original reporter's debugging:
response.contentcorrectly returned"I don't know."response.contentresolved the issue, suggesting intermittent model behavior rather than a code bugCurrent status
langchain-ai/docsrepo (not this repo), atsrc/oss/langchain/rag.mdxRecommendation
This issue can likely be closed as the tutorial code has been rewritten. The broader prompt injection discussion from the comments would be better suited as a feature request for documentation about RAG security best practices.