Analyze the effectiveness of different prompt injection defense methods based on their judgment criteria (content, destination, capability). Identify which methods are vulnerable to bypassing and which remain effective. Propose a workflow for implementing more robust defenses focusing on destination and capability checks.