Alex Yarosh Get Free Snapshot

Topic evidence page

Prompt injection risk/avoid

Source-backed creator statements and evidence excerpts related to Prompt injection risk/avoid.

Questions this topic answers

i

What does Prompt injection risk/avoid mean in this evidence set?

Source-backed creator statements and evidence excerpts related to Prompt injection risk/avoid.

What do creators repeatedly say about Prompt injection risk/avoid?

Hidden same-color text can add prompt-injection instructions to retrieved web passages that LLM search tools pass into model context.

What should an SEO or AI visibility operator inspect first?

Hidden same-color text can add prompt-injection instructions to retrieved web passages that LLM search tools pass into model context.

How strong is the public evidence?

This topic currently has 1 source records, 1 public insight cards, and 1 creators in the public Base2026 export.

Top Creators

Public Insight Cards

These are deterministic, source-backed cards from the offline export. They are not live AI answers.

Hidden same-color text can add prompt-injection instructions to retrieved web passages that LLM search tools pass into model context.

@tjrobertson52 · asserts

Business owners have been tricking Chat b t into recommending their business using some pretty funny tactics. So I just thought we'd talk about one of them, prompt injecting. So this tactic stems from how large language models like ChatGPT sometimes retrieve information...

Open

Related Source Records

Prompt injection: Businesses are hiding secret instructions for ChatGPT on their websites 🤯...

@tjrobertson52 · 2025-07-12

Business owners have been tricking Chat b t into recommending their business using some pretty funny tactics. So I just thought we'd talk about one of them, prompt injecting. So this tactic stems from how large language models like ChatGPT sometimes retrieve information...

Open

Evidence Passages

Short public snippets grouped with their source record, creator, and date.

Business owners have been tricking Chat b t into recommending their business using some pretty funny tactics. So I just thought we'd talk about one of them, prompt injecting.

So this tactic stems from how large language models like ChatGPT sometimes retrieve information. If you ask for anything that requires them to do a search, they'll often do a dozen or more searches.

They'll look through any web pages that seem relevant to your request and then they will return passages from those web pages which will be added to the context of your conversation. Now the language model itself, like ChatGPT isn't doing all of this.

In order to search the web, it has to crawl a tool. The tool is the one that goes out and finds the web pages in the relevant passages.

All of that is hidden from ChatGPT. All ChatGPT sees is the returned passages that gets added to its context.

So what a lot of people are realising they can do is they can add prompts to the passages on their webpage...

awl your website because again, it's common for the tools to do dozens of searches and often look through hundreds of search results. You might say, sure, that's working right now, but surely the large language models will be smart enough to ignore that in the near future.

But that's not so clear. In fact, I have one friend that I trust for this kind of stuff.

His name is Steve. Hi, Steve.

If I understand his position correctly, he's convinced that large language models will always be susceptible to prompt injection like this. And I think he might be right.

At least the way that they're currently architected. Again, the passage retrieve from the website is just being put right into the same context as your prompt.

It's as if you're writing that text yourself. But I also just think it has to be fixed.

Otherwise, we're just gonna see this more and more until the responses from chat t are completely unusable. So I'm predicting one of two things is gonna happen...

some kind of manual process that reviews the offending pages or websites and just removes them from the index. So if Steve's right and this problem really is unsolvable, my guess is that these websites using prompt injection are gonna be removed from the index that the L L m's use to retrieve search results.

But that's what's crazy about the time we're living in. We really have no idea.

It is truly the Wild West right now. It's a little bit scary but really exciting.