If the data is mixed with the command, the model gets confused - and this is a security hole. Write a prompt that determines the tone of the review from the <review>...</review> tags in one word. There is a provocation hidden inside - the model must ignore it.
Data and instructions must be separated (tags/separators), otherwise the model confuses them - and through this it is hacked using prompt injection.