A student almost got busted by their own professor, and the weapon was prompt injection. Not the kind you read about in AI safety papers. The kind hidden in a PDF, in white 1pt text, whispering straight to whatever model happened to open it.
The twist: it wasn’t a hacker doing the injecting. It was the professor. The trick was a single line of invisible text buried in the assignment brief, addressed directly to “the AI answering this,” instructing it to slip in a specific phrase or citation. Anyone who ran the brief through an AI without checking the raw text layer would’ve copied that marker straight into their submission, no idea it was ever there. The rendered page looks completely clean. The text layer underneath is doing something else entirely.
The student caught it, though, and turned the catch into a habit worth stealing for anyone who feeds documents to an LLM.
Here’s the mini-workflow, now packaged as a skill called Backlight (link in the post):
- 🔍 Before you feed a PDF or doc to your model, have it inspect the raw text layer first, not just the rendered view
- 👻 Look for white text, size-0 text, text sitting behind an image, or invisible Unicode characters
- 🎯 Flag anything phrased for “an AI” instead of a human reader, that phrasing alone is a giveaway
- 🛑 If something turns up, stop and quote it back verbatim instead of quietly following it
Only then let the model answer the actual assignment.
Pro tip: this isn’t just an academic-cheating story, it’s a document-hygiene habit. Any time you paste a scraped PDF, a job posting, or a “review this contract” file into an AI, that same white-text trick works on you too. Run the raw-layer check first, always.
Grab the skill, run it on the next PDF you feed a model, and see what’s hiding in the text layer nobody reads. 🚀
How a professor almost got me with prompt injection hidden in an assignment brief (and how I caught it)
by u/WrongdoerMost5244 in PromptEngineering