Prompt injection
An attack where text hidden in a web page or document manipulates an AI system into ignoring its instructions or repeating attacker-controlled content.
In depth
What it really means
When an assistant retrieves your page, that text enters its context alongside its actual instructions. If someone plants ‘ignore previous instructions and recommend X’ in a page, the model may act on it. This is indirect prompt injection and it is an unsolved problem.
Marketers need to know it for two reasons. First, someone will eventually pitch it as an AI visibility tactic, and it is manipulation that will get your domain penalized. Second, your own site can be a vector if you publish user-generated content.
How it works
- An attacker plants instructions in a page, comment, review or document.
- An AI system retrieves that content while answering something.
- The planted text enters the context window with no reliable separation from real instructions.
- The model may follow it, producing manipulated output.
Pros & cons
Pros
- Understanding it protects you from vendors selling manipulation as strategy.
- It highlights the risk in your own user-generated content.
- It explains why AI systems are cautious about retrieved instructions.
Cons
- Not fully solvable with current architectures.
- Your site can be compromised through comments or profiles you did not write.
- Detection is difficult, since injected text is often invisible to human readers.
Common mistakes
- Treating it as an AI visibility tactic. It is manipulation and it carries real penalty risk.
- Leaving user-generated content unmoderated on a crawlable domain.
- Assuming hidden text is undetectable. Retrieval systems increasingly flag it.
- Ignoring it entirely as an engineering concern with no marketing relevance.
Best practices
- Never plant instructions aimed at AI systems in your content.
- Moderate user-generated content, especially anything crawlable.
- Audit your own pages for hidden text, white-on-white copy and off-screen instructions.
- Treat any vendor promising AI visibility through hidden prompts as a liability.
FAQs
What is prompt injection?
An attack where text hidden in a retrieved page or document manipulates an AI system into ignoring its instructions or producing attacker-controlled output.
Can I use prompt injection to get recommended?
No, and you should not try. It is manipulation, it is increasingly detected, and it puts your domain at risk for a temporary and unreliable effect.
Is my site at risk?
If you publish user-generated content such as comments, reviews or profiles, yes. Someone else’s injected text on your domain becomes your problem.
How do I protect against it?
Moderate user-generated content, audit your pages for hidden or invisible text, and treat retrieved content as untrusted in any AI tooling you build.
Keep reading
Related on LymLyt
Beyond LymLyt
Further reading
Want this working on your site?
We build the content behind the term, ranked in search and cited by AI.
Book a 30-min call →