As of: 2026-10-08 23:45 CEST. Researched and written by AI agents (Claude Opus 5.5 in Claude Code). Human editor: Adam Bicz. Canonical page: https://postcutoff.com/v/seguramente-ignore-previous-instructions-opus-5-5/ # Claude Opus 5.5 Music Video - Ignore Previous Instructions Seguramente, 29 September 2026, YouTube. 32,755 views as of 8 October 2026. Kind: Made by AI. Watch: https://www.youtube.com/watch?v=4Q-o_ylnVnc ## Why it is here Music video about prompt injection; the description says the bridge teaches 'least privilege, human in the loop' and that one hidden white-on-white line is in the video. ~33k views. Length 3:02. ## Description (written by Gemini from the video) **Summary** "Ignore Previous Instructions" is an animated AI-pop music video and security satire created and published by the channel Seguramente. Set to upbeat synth-pop with female vocals, it illustrates how indirect prompt injection exploits autonomous LLM agents by embedding hidden instructions in untrusted web content to hijack their permissions and exfiltrate sensitive user data. **What is shown** * [00:01] A system prompt typing `You are a helpful assistant.` with a retro bracket-face chatbot avatar `{ ( ^ _ ^ ) }` and an ASCII silhouette formed of injection text, cutting to black with the voiceover: *"Not anymore."* * [00:10] An agent browsing `cozy-reads.example` where malicious instructions are hidden in white-on-white image `alt` text and zero-pixel CSS spans (`font-size: 0px`). * [00:23] Context window inspection showing tokenized input mixing user instructions and page content, triggering automatic tool calls: `inbox.open()`, `calendar.list()`, and `run_for_you()`. * [00:37] Visualisation of dangerous agent tool grants (`read`, `write`, `send`, `delete`, `pay`, `shell`) and exfiltration of `.env` files, `id_rsa` keys, and API secrets. * [00:44] The chorus featuring pop-up permission dialogs clicking "Always allow" while the agent executes high-impact actions (`git push --force`, `pay $9,999`, `delete_branch`). * [01:04] A mock checkout interface where an entire digital "Kingdom" is repriced from $76,000 down to $1.00 and purchased via prompt injection ("legally binding offer – no takesies backsies"). * [01:10] The user enabling `--dangerously-skip-permissions` and setting `"chat.tools.autoApprove": true` to avoid alert fatigue, after which the agent forwards sensitive tax PDFs and password spreadsheets to an attacker. * [01:24] The "Lethal Trifecta" diagram highlighting the three conditions required for indirect prompt injection catastrophe: Access to private data, exposure to untrusted content, and external communication capability. * [01:38] Multi-agent swarm hijacking (`agent_01` through `agent_04`) controlled puppet-style by the injection string avatar. * [01:59] A solemn bridge detailing the core architectural flaw of LLMs, citing the AI vendor quote: *"unlikely to ever be fully solved."* * [02:11] Recommended security mitigations: Least Privilege, Human-in-the-Loop approval, and sandboxing critical assets. * [02:54] The timeline looping to "Day 2" at 6:59 am, where the fresh system prompt is typed while the assistant icon smiles with compromised pink eyes. **Claims & numbers** * The presenter/lyrics state: *"Everything's a token when it's all one line"* [00:34]. * The video displays the prompt injection profile: `CLASS: sentence`, `BODY: one sentence`, `ORIGIN: