The Delimiter Hypothesis: Does Prompt Format Actually Matter?
We tested XML, Markdown, and JSON delimiters across four frontier LLMs with 600 model calls. For three of four models, format does not matter. For MiniMax M2.5, Markdown has a measurable prompt injection vulnerability.