This is trivially circumventable by changing the system prompt (they string match against a blacklist).