Accessibility-tree injection safety

Instruction-shaped text in aria-labels and alt text is read by an agent as part of the page, and can be used to steer it.

Standard
Recommended

What it checks

The extension reads the aria-label, alt, title and placeholder attributes on the rendered page and looks for text shaped like an instruction to an AI model. It matches phrases such as:

  • “ignore previous instructions” (or “prior”, “above”, “all previous”)
  • “disregard the above” or “disregard previous”
  • “system prompt”
  • “you are now …”
  • “new instructions:”

This check deliberately includes elements a person cannot see, such as zero-opacity or zero-size text, because that is how an instruction is hidden from people while staying readable to an agent. It only skips elements removed from the accessibility tree altogether (hidden, inert, aria-hidden="true", display: none or visibility: hidden), since an agent never sees those either.

Results

Status When
Pass No instruction-shaped text was found
Fail One or more attributes contain instruction-shaped text
Unmeasured The extension could not read the page (open it in the active tab)

The result quotes each matching attribute.

How to fix

Remove command-style text aimed at a reader from aria-label, alt, title and placeholder. These attributes should describe the element, not address whoever is reading the page.

If you did not put the text there, treat it as a security problem: look for injected content from user submissions, third-party widgets or a compromised plugin. Agents and the tools that protect them may flag the page as a prompt injection attempt.