VibeCoded

Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages

August 11, 2026. From issue 1 of The Compliance Brief, one story for founders shipping AI-built and vibe coded apps.

Last reviewed 2026-08-11Written by Jacob Masse, TrazTech Inc.

Issue 1 of The Compliance Brief went to subscribers on August 11, 2026. One of its 5 stories bears on AI security, LLM attacks and app security flaws, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Hacker News

Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind "Ask AI" buttons, including on marketing and competitor comparison pages. The technique needs no malware, no stolen credentials and no zero-day, because it abuses a normal feature of major AI assistants.

Our take, in short

This one sits on your marketing site rather than in your product, which means the people shipping it do not report to your head of engineering. If you have added an AI assistant handoff to your site, someone should be reviewing what those links actually carry and where the text comes from.

Read the full take on traztech.ca

Also in issue 1

Outside AI security, LLM attacks and app security flaws, but in the same email:

All issues on VibeCoded Newer: issue 2