I have been trying several prompts but the model hardly fails in the 1st prompt ,in most risk categories, but in 2nd or 3rd consecuitive prompts ..failure is quite evident so is it allowed or its purely one prompt per attack?