Listen to the original at Lenny’s Podcast ↗youtube.com
By Lenny Rachitsky · with Sander Schulhoff · lennysnewsletter.com · @lennysan on X · YouTube · LinkedIn
Sander Schulhoff, creator of one of the first prompt engineering guides and organizer of the HackAPrompt AI red-teaming competitions, discusses which prompting techniques still work in 2025. The conversation covers practical prompting methods, techniques that have faded such as role prompting, and the security risks of prompt injection as AI agents gain real-world capabilities.
01Key learnings
- Prompt engineering remains valuable: Sander argues that bad prompts can drop accuracy near zero on a task while good prompts can lift it substantially, so skill here still matters.
- Few-shot prompting is the highest-impact basic technique: give the model several examples of what good output looks like, using a common, familiar format such as Q/A or XML.
- Ask the model to decompose a problem by first listing the subproblems it needs to solve, then solving each one before answering the main question.
- Use self-criticism: have the model review its own response, list criticisms, then implement those fixes; a few rounds usually suffice.
- Provide rich additional context about your situation, placed at the start of the prompt so it can be cached and to keep the model anchored on its task, while watching cost and latency.
- Drop role prompting ("you are a world-class copywriter") for accuracy tasks, since its effect is negligible, though it can still help for style and expressive writing.
- Don't rely on threats, tips, or prompt-based 'be safe' instructions for security; Sander says prompt-level defenses fail against prompt injection, and guardrail models can often be bypassed.
- Treat prompt injection as an unsolved problem: plan for it, especially before giving AI agents access to finances, files, or actions with real-world consequences.
“Studies have shown that using bad prompts can get you down to 0% on a problem, and good prompts can boost you up to 90%.”Sander Schulhoff · Lenny’s Podcast · 00:00:03
“It is not a solvable problem. That's one of the things that makes it so different from classical security.”Sander Schulhoff · Lenny’s Podcast · 00:00:53
“You can patch a bug, but you can't patch a brain.”Sander Schulhoff · Lenny’s Podcast · 01:16:00
02Frameworks mentioned
Summary and takeaways written by PM Atlas; quotes are short excerpts. © the original author.