Skip to content

Hidden text on the page contains instructions written for an AI, not a human

This check scans the page source for hidden text, inside an HTML comment or an invisible element, that reads like instructions directed at an AI system rather than at a human visitor. This is a known attack technique called indirect prompt injection. On this site, this kind of hidden AI-directed text was found on the page. Hidden instruction text can hijack an AI browsing agent, such as Claude's Computer Use, ChatGPT Atlas, or Perplexity Comet, when it's acting on behalf of a visitor browsing the site, or it can poison how AI answer engines describe the brand to people asking about it. Because it's invisible to humans reading the page normally and invisible to conventional security scanners, it's a genuinely new blind spot most sites have never checked for. Your developer should remove the hidden instruction text from the page source immediately. If this text wasn't put there deliberately by anyone on your team, treat it as a sign the site or a content management system account may have been compromised, and investigate how it got there before assuming it's an isolated issue.

Why this matters

Hidden instruction text can hijack an AI browsing agent, such as Claude's Computer Use, ChatGPT Atlas, or Perplexity Comet, when it's acting on behalf of a visitor browsing the site, or it can poison how AI answer engines describe the brand to people asking about it. Because it's invisible to humans reading the page normally and invisible to conventional security scanners, it's a genuinely new blind spot most sites have never checked for.

How to fix it

Your developer should remove the hidden instruction text from the page source immediately. If this text wasn't put there deliberately by anyone on your team, treat it as a sign the site or a content management system account may have been compromised, and investigate how it got there before assuming it's an isolated issue.