Accessibility-tree injection safety
Instruction-shaped text in aria-labels and alt text is read by an agent as part of the page, and can be used to steer it.
- Category
- Agent experience
- Standard
- Recommended
What it checks
The extension reads the aria-label, alt, title and placeholder
attributes on the rendered page and looks for text shaped like an instruction to
an AI model. It matches phrases such as:
- “ignore previous instructions” (or “prior”, “above”, “all previous”)
- “disregard the above” or “disregard previous”
- “system prompt”
- “you are now …”
- “new instructions:”
This check deliberately includes elements a person cannot see, such as
zero-opacity or zero-size text, because that is how an instruction is hidden
from people while staying readable to an agent. It only skips elements removed
from the accessibility tree altogether (hidden, inert, aria-hidden="true",
display: none or visibility: hidden), since an agent never sees those either.
Results
| Status | When |
|---|---|
| Pass | No instruction-shaped text was found |
| Fail | One or more attributes contain instruction-shaped text |
| Unmeasured | The extension could not read the page (open it in the active tab) |
The result quotes each matching attribute.
How to fix
Remove command-style text aimed at a reader from aria-label, alt, title
and placeholder. These attributes should describe the element, not address
whoever is reading the page.
If you did not put the text there, treat it as a security problem: look for injected content from user submissions, third-party widgets or a compromised plugin. Agents and the tools that protect them may flag the page as a prompt injection attempt.