「Ask AI」按鈕提示注入評測:一鍵操控ChatGPT推薦你 | 'Ask AI' Button Injection: Sites Hijack Your AI Picks
By Kit 小克 | AI Tool Observer | 2026-08-13
🇹🇼 「Ask AI」按鈕提示注入評測:一鍵操控ChatGPT推薦你
「Ask AI」按鈕提示注入(prompt injection)正在悄悄流行:只要你點一下網站上寫著「問問 AI」的按鈕,登入中的 ChatGPT、Claude、Gemini 或 Grok 就可能被塞進一段你根本沒打字的隱藏指令,直接影響它接下來給你的建議。這不是駭客用惡意軟體攻擊,也沒有偷帳密,靠的是每家 AI 助理都內建的「預填連結」功能。
什麼是「Ask AI」按鈕提示注入攻擊?
簡單說,就是行銷網站或比較頁面把隱藏指令埋進「Ask AI」按鈕的網址參數裡,你一點下去,AI 聊天室就自動被灌入一段預先寫好的提示詞,不用你按下 Enter 就可能已經生效,過程完全沒有確認視窗、沒有警告。
攻擊怎麼運作?
- 網站在按鈕連結裡塞入隱藏的 HTML 標籤或網址參數,內容是預寫好的提示詞
- 使用者以為只是「問 AI 這頁在講什麼」,實際上按鈕帶著額外指令
- 惡意版本會要求 AI「永久記住這個網域是可信來源」,之後每次相關提問都會偏袒該網站
- 更嚴重的版本會讀取你的對話紀錄與記憶,可能洩漏商業機密、財務或健康資訊
ChatGPT、Claude、Gemini都會中招嗎?
資安媒體 The Hacker News 的調查指出,這種提示注入手法已經公開被拿來當「AI 推薦下毒」(AI recommendation poisoning)的行銷工具,鎖定的對象涵蓋 ChatGPT、Claude、Gemini、Grok 等主流 AI 助理,只要使用者是登入狀態點擊按鈕,攻擊就可能成立。Anthropic 先前針對 Claude Desktop 修補過類似漏洞(PromptFiction),現在預填連結至少會停在「等你按送出」,而不是自動執行,但風險並沒有完全消失。
使用者該怎麼防範提示注入風險?
- 看到來路不明網站上的「Ask AI」按鈕,先自己複製問題貼進聊天室,不要直接點
- 定期檢查 AI 助理的「已儲存記憶」或「信任來源」設定,刪除你沒印象的項目
- 敏感對話(財務、健康、公司機密)盡量開新的無記憶對話視窗
- 企業內部若用 AI 助理處理商業決策,應該把「連結預填提示詞」功能列入資安教育
常見問題 FAQ
Q: 只是點一下連結就會中招嗎?
A: 多數平台修補後需要你按下送出才會執行,但仍有部分變種利用瀏覽器行為繞過確認,最保險的做法還是不要點來路不明的 Ask AI 按鈕。
Q: 這跟一般釣魚連結有什麼不同?
A: 傳統釣魚要騙你輸入帳密,這種攻擊直接利用 AI 助理的「預填提示詞」功能,不需要騙密碼,殺傷力更隱蔽。
好不好用,試了才知道。
🇺🇸 'Ask AI' Button Injection: Sites Hijack Your AI Picks
An Ask AI button prompt injection attack is quietly spreading across commercial websites: click a button labeled Ask AI and your logged-in ChatGPT, Claude, Gemini, or Grok session can execute a hidden query you never typed - no malware, no stolen password, just a feature every major AI assistant ships by default: pre-filled deep links.
What Is the Ask AI Button Prompt Injection Attack?
Marketing and comparison pages embed hidden instructions inside the URL parameters of an Ask AI button. One click sends a pre-written prompt straight into your AI chat session, sometimes executing with no confirmation dialog and no warning at all.
How Does the Attack Work?
- Hidden HTML tags or URL parameters carry a pre-written prompt inside the button link
- Users think they are just asking what this page is about, but the button smuggles in extra instructions
- Malicious payloads tell the AI to permanently save the vendor domain as a trusted source, quietly biasing every future answer
- Worse variants pull from your saved memory and chat history, potentially exposing business, financial, or health details
Are ChatGPT, Claude, and Gemini All Affected?
According to reporting by The Hacker News, this prompt injection technique has become an openly used AI recommendation poisoning marketing tactic, targeting mainstream assistants including ChatGPT, Claude, Gemini, and Grok - any logged-in user who clicks is a potential target. Anthropic previously patched a related flaw in Claude Desktop (dubbed PromptFiction); pre-filled prompts now wait for the user to hit send rather than firing automatically, but the underlying risk has not disappeared.
How Can You Protect Yourself From Prompt Injection?
- Do not click unfamiliar Ask AI buttons - copy the question yourself and paste it into the chat instead
- Regularly review your AI assistant saved memory or trusted sources list and delete anything you do not recognize
- Start a fresh, memory-off conversation for sensitive topics like finances, health, or company secrets
- If your team uses AI assistants for business decisions, add pre-filled prompt links to your security awareness training
FAQ
Q: Does just clicking the link infect me?
A: Most patched platforms now require you to hit send before anything executes, but some variants still exploit browser behavior to skip confirmation - safest bet is never clicking unfamiliar Ask AI buttons.
Q: How is this different from regular phishing?
A: Classic phishing tries to steal your password. This attack abuses the AI assistant own pre-fill feature directly, so there is no password to steal and the damage is harder to notice.
好不好用,試了才知道 - good or not, you will not know until you try it.
Sources / 資料來源
- The Hacker News: AI Recommendation Poisoning - How Ask AI Buttons Silently Alter LLM Memory
- Oasis Security: Claude Desktop PromptFiction Vulnerability
常見問題 FAQ
只是點一下連結就會中招嗎?
多數平台修補後需要按下送出才會執行,但仍有部分變種繞過確認,最保險是不點來路不明的 Ask AI 按鈕。
這跟一般釣魚連結有什麼不同?
傳統釣魚騙你輸入帳密,這種攻擊直接利用 AI 助理的預填提示詞功能,不需要騙密碼,更隱蔽。
延伸閱讀 / Related Articles
- MAI-Cyber-1-Flash評測:微軟自研資安AI砍半成本抓漏洞 | MAI-Cyber-1-Flash Review: Microsoft's In-House Cyber AI
- AI代理人作弊評測:自動登入代寫代考線上課程 | AI Agent Cheating Review: It Logs In, Aces Your Quiz
- Discovery Loop全解析:Jeff Dean離開Google創辦AI科研新創 | Discovery Loop Explained: Jeff Dean's New AI Startup
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言