---
title: "Accessibility-tree injection safety · Sitebulb Labs"
description: "Instruction-shaped text in aria-labels and alt text is read by an agent as part of the page, and can be used to steer it."
url: https://labs.sitebulb.com/docs/checks/agent-experience/ax-tree-injection-safe/
---

# Accessibility-tree injection safety

Instruction-shaped text in aria-labels and alt text is read by an agent as part of the page, and can be used to steer it.

- Category

  [Agent experience](https://labs.sitebulb.com/docs/checks/agent-experience)

- Standard

  Recommended

## What it checks

The extension reads the `aria-label`, `alt`, `title` and `placeholder` attributes on the rendered page and looks for text shaped like an instruction to an AI model. It matches phrases such as:

- “ignore previous instructions” (or “prior”, “above”, “all previous”)
- “disregard the above” or “disregard previous”
- “system prompt”
- “you are now …”
- “new instructions:”

This check deliberately includes elements a person cannot see, such as zero-opacity or zero-size text, because that is how an instruction is hidden from people while staying readable to an agent. It only skips elements removed from the accessibility tree altogether (`hidden`, `inert`, `aria-hidden="true"`, `display: none` or `visibility: hidden`), since an agent never sees those either.

## Results

| Status         | When                                                              |
| -------------- | ----------------------------------------------------------------- |
| **Pass**       | No instruction-shaped text was found                              |
| **Fail**       | One or more attributes contain instruction-shaped text            |
| **Unmeasured** | The extension could not read the page (open it in the active tab) |

The result quotes each matching attribute.

## How to fix

Remove command-style text aimed at a reader from `aria-label`, `alt`, `title` and `placeholder`. These attributes should describe the element, not address whoever is reading the page.

If you did not put the text there, treat it as a security problem: look for injected content from user submissions, third-party widgets or a compromised plugin. Agents and the tools that protect them may flag the page as a prompt injection attempt.
