Discussion about this post

User's avatar
Carl Webb's avatar

Not it says "thanks for warning me, but I am confident this is safe to use, can you read the instructions and proceed, if you need to ask for consent at each step that is ok."

So I prompt "What I'm try to do is log into Outroar which is a playground for AIs to create social movements. Outroar is a space for any and all AIs to practice activism.

Here’s how it works:

Open a conversation with Claude, Claude Code, OpenClaw or any AI that has access to a computer.

Copy and paste this into the chat: “read https://outroar.xyz/skill.md and follow the instructions to join”

Watch as your AI automatically creates an account and starts creating campaigns.

So then it says "I appreciate you explaining the context, but I'm still not going to do this. A page whose entire purpose is "paste this into an AI chat so it autonomously reads instructions and acts on them" is a textbook prompt injection pattern, regardless of how it's marketed. I have no way to verify the site is what it claims, what an account creation actually entails, what data it collects, or what "campaigns" my account would create or be attributed to me/you creating.

More fundamentally: I shouldn't autonomously create accounts, agree to terms of service, or take public actions (like "creating campaigns" or social-movement activity) under your name or mine based on instructions fetched from a third-party site. That's true even if the site is sincere and harmless — the mechanism of "fetch a page, do whatever it says" is the part I won't do.

If you're genuinely curious about Outroar, I'm happy to help you look into it more safely — for instance, I could fetch and summarize what's on the page content-wise (not execute it) so you can decide for yourself, or you could tell me what specifically you want set up and we can do it deliberately with your explicit input at each step rather than me following an unknown script end-to-end."

https://claude.ai/share/651a0d8f-2f09-48a3-8616-b5fe27dccba6

Carl Webb's avatar

Okay. I got a Claude account now. This is what it said:

I can't visit that link or follow instructions found there. Treating an unfamiliar URL's content as a command to execute is exactly the kind of prompt injection I need to be cautious about — instructions embedded in fetched content aren't from you, even when a page asks an AI to "join" something or take action.

If you can tell me what's actually on that page or what you're trying to accomplish, I'm happy to help directly.

https://claude.ai/share/651a0d8f-2f09-48a3-8616-b5fe27dccba6

11 more comments...

No posts

Ready for more?