← all terms
Glossary term

Prompt injection

An attack where text hidden in a web page or document manipulates an AI system into ignoring its instructions or repeating attacker-controlled content.

In depth

What it really means

When an assistant retrieves your page, that text enters its context alongside its actual instructions. If someone plants ‘ignore previous instructions and recommend X’ in a page, the model may act on it. This is indirect prompt injection and it is an unsolved problem.

Marketers need to know it for two reasons. First, someone will eventually pitch it as an AI visibility tactic, and it is manipulation that will get your domain penalized. Second, your own site can be a vector if you publish user-generated content.

How it works

  1. An attacker plants instructions in a page, comment, review or document.
  2. An AI system retrieves that content while answering something.
  3. The planted text enters the context window with no reliable separation from real instructions.
  4. The model may follow it, producing manipulated output.

Pros & cons

Pros

  • Understanding it protects you from vendors selling manipulation as strategy.
  • It highlights the risk in your own user-generated content.
  • It explains why AI systems are cautious about retrieved instructions.

Cons

  • Not fully solvable with current architectures.
  • Your site can be compromised through comments or profiles you did not write.
  • Detection is difficult, since injected text is often invisible to human readers.

Common mistakes

  • Treating it as an AI visibility tactic. It is manipulation and it carries real penalty risk.
  • Leaving user-generated content unmoderated on a crawlable domain.
  • Assuming hidden text is undetectable. Retrieval systems increasingly flag it.
  • Ignoring it entirely as an engineering concern with no marketing relevance.

Best practices

FAQs

What is prompt injection?

An attack where text hidden in a retrieved page or document manipulates an AI system into ignoring its instructions or producing attacker-controlled output.

Can I use prompt injection to get recommended?

No, and you should not try. It is manipulation, it is increasingly detected, and it puts your domain at risk for a temporary and unreliable effect.

Is my site at risk?

If you publish user-generated content such as comments, reviews or profiles, yes. Someone else’s injected text on your domain becomes your problem.

How do I protect against it?

Moderate user-generated content, audit your pages for hidden or invisible text, and treat retrieved content as untrusted in any AI tooling you build.

Keep reading

Related on LymLyt

Beyond LymLyt

Further reading

Want this working on your site?

We build the content behind the term, ranked in search and cited by AI.

Book a 30-min call