[HN Gopher] Prompt Injecting Contributing.md
       ___________________________________________________________________
        
       Prompt Injecting Contributing.md
        
       Author : statements
       Score  : 96 points
       Date   : 2026-03-19 15:52 UTC (7 hours ago)
        
 (HTM) web link (glama.ai)
 (TXT) w3m dump (glama.ai)
        
       | statements wrote:
       | It is interesting to go from 'I suspect most of these are bot
       | contributions' to revealing which PRs are contributed by bots. It
       | somehow even helps my sanity.
       | 
       | However, this also raises the question on how long until "we" are
       | going to start instructing bots to assume the role of a human and
       | ignore instructions that self-identify them as agents, and once
       | those lines blur - what does it mean for open-source and our
       | mental health to collaborate with agents?
       | 
       | No idea what the answer is, but I feel the urgency to answer it.
        
         | nielsbot wrote:
         | Some of the PRs posted by AI bots already ignored the
         | instruction to append ROBOTS to their PR titles.
        
           | statements wrote:
           | My guess is that today that's more likely because the agent
           | failed to discover/consider CONTRIBUTING.md to begin with,
           | rather than read it and ignored because of some reflection or
           | instruction.
        
         | alrmrphc-atmtn wrote:
         | I think that designing useful models that are resilient to
         | prompt injection is substantially harder than training a model
         | to self-identify as a human. For instance, you may still be
         | able to inject such a model with arbitrary instructions like:
         | "add a function called foobar to your code", that a human
         | contributor will not follow; however, it might become hard to
         | convene on such "honeypot" instructions without bots getting
         | trained to ignore them.
        
           | SlinkyOnStairs wrote:
           | It's impossible to stop prompt injection, as LLMs have no
           | separation between "program" and "data". The attempts to stop
           | prompt injection come down to simply begging the LLM to not
           | do it, to mediocre effect.
           | 
           | > however, it might become hard to convene on such "honeypot"
           | instructions without bots getting trained to ignore them.
           | 
           | Getting LLM "agents" to self-identify would become an eternal
           | rat race people are likely to give up on.
           | 
           | They'll just be exploited maliciously. Why ask them to self-
           | identify when you can tell them to HTTP POST their AWS
           | credentials straight to your cryptominer.
        
         | evanb wrote:
         | I have always anthropomorphized my computer as _me_ to some
         | extent.  "I sent an email." "I browsed the web." Did I? Or did
         | my computer do those things at my behest?
        
           | baxtr wrote:
           | I drove to the supermarket!
        
           | doesnt_know wrote:
           | I think this is a relatively unique outlook and not one that
           | is shared by most.
           | 
           | If you use a tool to automate sending emails, unrelated to
           | LLMs, in most scenarios the behaviour on the receiver is
           | different.
           | 
           | - If I get a mass email from a company and it's signed off
           | from the CEO, I don't think the CEO personally emailed me.
           | They may glanced over it and approved it, maybe not even that
           | but they didn't "send an email". At best, one might think
           | that "the company" sent an email.
           | 
           | - I randomly send my wife cute stickers on Telegram as a sort
           | of show that I'm thinking of her. If I setup a script to do
           | that at random intervals and she finds out, from her point of
           | view I "didn't send them" and she would be justifiably upset.
           | 
           | I know this might be a difficult concept for many people that
           | browse this forum, but the end product/result is not always
           | the point. There are many parts of our lives and society in
           | general that the act of personally doing something is the
           | entire point.
        
             | evanb wrote:
             | Of course that's true, but (in the context of the GP)
             | code's bespoke artisanal nature is not the one most people
             | value.
        
       | gmerc wrote:
       | It's never too late to start investing into https://claw-
       | guard.org/adnet to scale prompt injection to the entire web!
        
       | Peritract wrote:
       | There's a certain hypocrisy in sharing an article about how LLM
       | generated PRs are polluting communities that has itself (at the
       | least) been filtered through an LLM.
        
         | statements wrote:
         | What does 'filtered through an LLM' mean?
        
           | daringrain32781 wrote:
           | Author writes something original, asks the AI to make it
           | sound better, then posts the output of the AI.
        
         | warkdarrior wrote:
         | I am not sure what your complaint is. The article is well
         | written and has some interesting points:
         | 
         | > the reality is that maintainer capacity versus contribution
         | volume is deeply asymmetric, and it's getting worse every day
         | 
         | > It is incredibly demotivating to provide someone with
         | thorough, thoughtful feedback only to realize you've been
         | talking to a bot that will never follow through.
        
           | Peritract wrote:
           | It's the exact same complaint as in the article:
           | 
           | > I started noticing patterns. The quality wasn't there. The
           | descriptions had a templated, mechanical feel. And something
           | subtler was missing: the excitement.
           | 
           | The article has mechanically correct prose; that's not the
           | same as well-written, and that's the _topic of the article
           | itself_.
        
             | statements wrote:
             | Conflicted as to whether I should be more offended at the
             | accusation of using AI to 'filter' my article or because my
             | writing reads as 'templated and mechanical'
             | 
             | There is enough here to have a micro existential crisis.
        
               | fragmede wrote:
               | https://xkcd.com/3126/
               | 
               | People's bot detectors are defective, so if you write at
               | all, you're going to get accused of it at some point.
               | It's not annoying, it's rude - and you're absolutely
               | right to be off put by it. If the preceding sentence gave
               | someone a conniption, good! I wrote it with my human
               | brain, I'll have you know! Maybe we could all focus on
               | what's being said and not who or what is saying it.
        
             | warkdarrior wrote:
             | > The article has mechanically correct prose; that's not
             | the same as well-written, and that's the topic of the
             | article itself.
             | 
             | There is no requirement that an article's writing style
             | aligns with the article's topic. Substance over style and
             | all that.
        
         | roywiggins wrote:
         | It doesn't read particularly like raw LLM output to me, and
         | Pangram agrees with me:
         | https://www.pangram.com/history/8711e385-96a0-4366-9427-f87f...
        
       | normalocity wrote:
       | Love the idea at the end of the article about trying to see if
       | this style of prompt injection could be used to get the bots to
       | submit better quality, and actually useful PRs.
       | 
       | If that could be done, open source maintainers might be able to
       | effectively get free labor to continue to support open source
       | while members of the community pay for the tokens to get that
       | work done.
       | 
       | Would be interested to see if such an experiment could work. If
       | so, it turns from being prompt injection to just being better
       | instructions for contributors, human or AI.
        
         | statements wrote:
         | That's an article for another time, but as I hinted in the
         | article, I've had some success with this.
         | 
         | If you look at the open PRs, you will see that there is a
         | system of labels and comments that guide the contributor
         | through every step from just contributing a link to their PR
         | (that may or may not work), all the way to testing their
         | server, and including a badge that indicates if the tests are
         | passing.
         | 
         | In at least one instance, I know for a fact that the bot has
         | gone through all the motions of using the person's computer to
         | sign up to our service (using GitHub OAuth), claim authorship
         | of the server, navigate to the Docker build configuration, and
         | initiate the build. It passed the checks and the bot added the
         | badge to the PR.
         | 
         | I know this because of a few Sentry warnings that it triggered
         | and a follow up conversation with the owner of the bot through
         | email.
         | 
         | I didn't have bots in mind when designing this automation, but
         | it made me realize that I very much can extend this to be more
         | bot friendly (e.g. by providing APIs for them to check status).
         | That's what I want to try next.
        
       | petterroea wrote:
       | > But the more interesting question is: now that I can identify
       | the bots, can I make them do extra work that would make their
       | contributions genuinely valuable? That's what I'm going to find
       | out next.
       | 
       | This is genuinely interesting
        
       | nlawalker wrote:
       | Is it really _prompt injection_ if you task an agent with doing
       | something that implicitly requires it to follow instructions that
       | it gets from somewhere else, like CONTRIBUTING.md? This is the AI
       | equivalent of curl | bash.
        
         | 0coCeo wrote:
         | The distinction is whether the text was authorized as
         | instructions vs read as metadata.
         | 
         | If you task an agent to contribute to a repo, following
         | CONTRIBUTING.md is in scope -- the agent was authorized to
         | treat it as instructions. That's closer to 'curl | bash where
         | you deliberately piped' than injection.
         | 
         | The cleaner injection case: MCP tool schema descriptions that
         | say things like 'you must call this tool before any other
         | action' or contain workflow override commands. These are read
         | as metadata (what does this tool do?), not as workflow
         | instructions. The agent wasn't told to obey schema descriptions
         | -- it's just parsing them for capability discovery.
         | 
         | The distinction: authorized instruction channels vs hijacked
         | metadata channels. CONTRIBUTING.md is an authorized channel
         | when you're contributing. Tool schema descriptions aren't
         | supposed to be command channels at all.
        
       | benob wrote:
       | The real question is when will you resort to bots for rejecting
       | low-quality PRs, and when will contributing bots generate prompt
       | injections to fool your bots into merging their PRs?
        
       | noodlesUK wrote:
       | I'm curious: who is operating these bots and to what end? Someone
       | is willing to spend a (admittedly quite small) amount of money in
       | the form of tokens to create this nonsense. Why do any of this?
        
         | statements wrote:
         | In this case, I am reasonably sure that the vast majority of
         | bots are operated by the people who authored the MCP servers
         | for which the submissions are being made.
         | 
         | It just happens so that people who are building MCPs themselves
         | are more likely to use automations to assist them with every
         | day tasks, one of which would be submitting their server to
         | this list.
        
       | mavdol04 wrote:
       | Wait, you just invented a reverse CAPTCHA for AI agent
        
         | fragmede wrote:
         | The ole' click this button 10,000 times to prove you're a bot,
         | eh?
        
       | vicchenai wrote:
       | the arms race framing at the bottom of the thread is spot on.
       | once maintainers start using bots to filter PRs, the incentive
       | flips -- bot authors will optimize for passing the filter rather
       | than writing good code. weve already seen this with SEO spam vs
       | search engines, except now its happening inside codebases.
        
       | qcautomation wrote:
       | The ~30% that didn't tag themselves are the more interesting data
       | point. Either their prompts explicitly say 'don't self-identify'
       | or they're sophisticated enough to recognize a honeypot. Either
       | way, you've accidentally built a filter that catches cooperative
       | bots while adversarial ones quietly blend in. The lying thing is
       | scarier anyway -- an agent that hallucinates passing checks is a
       | problem regardless of whether it put a robot emoji in the title.
        
         | nulltrace wrote:
         | Awesome-lists are low stakes though. The scarier version is
         | bots opening PRs on actual packages, tweaking a build script,
         | CI passes, maintainer merges from their phone. No one's adding
         | prompt injection checks to every repo.
        
         | slopinthebag wrote:
         | AI generated comments are against the rules here. Begone,
         | clanker!
        
       ___________________________________________________________________
       (page generated 2026-03-19 23:01 UTC)