@bd808 @brooke Since it's a fixed model on the user's device, it should be possible to brute force engineer prompt attacks where you serve text that's entirely benign interpreted as natural language, but where the model "summarizes" it to something very embarrassing to Mozilla.