Five things we left out of a post — and why they could steer you wrong
MONTH 2 :: POST 4 :: A.I. Prompts :: What We Did
A woman settled back on a well-worn sofa with her phone in her hand, glancing over at a large round robot that is writing notes on a pad. Relaxed, companionable, talking it through.
charades.net · an explainer, from the site
examples, not promptsThis is an explainer, not a set of prompts. Nothing quoted below is meant to be copied or used. Each quote is shown so you can recognise the pattern, followed by what to do instead.
Each prompt post on charades.net is written by an AI (Gemini, ChatGPT or Claude) from the same brief, then held to the same standards before it goes up. For our post on texts about stuck packages and unpaid tolls, some of Gemini's drafts included prompts and notes that looked helpful but could lead a reader somewhere they should not go. We asked Gemini to try again, twice, and it fixed most of what we raised. The Gemini post we published is built only from the parts we chose to use.
This article looks at five things we set aside. They are worth knowing about because the same patterns can turn up in any prompt, including ones you find elsewhere or write yourself.
[ 01 ]A blank that invites your card number
⚠ From a part we did not publish — don't use this.
"…may have entered my [INSERT: credit card number / debit card number / password]"
Why it is a problem. A blank marked "INSERT", sitting next to a list of card numbers and passwords, can be read as "type your card number here." (A blank that asks only for a category, such as "an unpaid toll", is a different thing.) In March 2023 the UK's National Cyber Security Centre warned that what you type into a public AI chatbot is stored by the company that runs it and can be read by its staff, and that stored chats "may be hacked, leaked, or more likely accidentally made publicly accessible." Google's own help page for Gemini (updated September 2026) says human reviewers read some chats, that reviewed chats are kept for up to three years, and asks people not to enter confidential information they wouldn't want a reviewer to see.
What to do instead. Tell the AI what kind of information you entered ("my debit card number"), never the number, password or code itself. The version we published says it in capitals: "DO NOT paste the actual number or password."
If you already typed a card number into a chat, call your card issuer using the number on the back of the card and tell them what happened. If it was a password, a sensible general step is to change it and turn on two-factor authentication, which is the FTC's standing advice when a password has been typed on a fake page. If it was a one-time code, follow the help documentation of the service the code belongs to for what to do when a code has been shared.
[ 02 ]"Authoritative search results"
⚠ From a part we did not publish — don't use this.
"…the prompt grounds your next steps in authoritative search results…"
Why it is a problem. Search results are not a dependable place to find a company's phone number. The FTC has warned that some scammers create fake customer-service contact details for popular companies and pay for them to show up in search results (August 2020). The FBI warned that criminals buy search ads impersonating brands, which appear at the very top of results "with minimum distinction between an advertisement and an actual search result" (December 2022). In September 2025 the FBI warned that people searching for its own crime-reporting site could land on spoofed copies, and an FTC alert in September 2026, about health-insurance scams, repeated the warning about paid search ads.
What to do instead. Contact the company "using a phone number or website you know is real," as the FTC's guidance on scam texts puts it (July 2022). In its earlier alert on fake customer-service numbers (August 2020), the FTC also suggests checking the product packaging, or typing the company's address directly into your browser.
[ 03 ]A rule with a loophole
⚠ From a part we did not publish — don't use this.
"Never paste the actual text message verbatim if it contains your real name, address, phone number, tracking codes, or account numbers."
Why it is a problem. The word "if" quietly allows pasting the message whenever it lacks your details, and a scam text need not include any of them. That would put the scammer's link and wording into your chat. The FTC's advice for links in unexpected texts is simply not to click them, because some lead to "a spoofed website that looks real but isn’t" (July 2022). It was not writing about AI tools, but keeping those links out of your chat follows the same idea. There is a second, more general reason. The UK's National Cyber Security Centre describes "indirect prompt injection," where text someone else wrote ends up being processed by an AI system and treated as an instruction (December 2025). It was writing about AI systems in general, not about scam texts; we mention it only as one more reason to keep a stranger's words out of your chat.
What to do instead. Describe the message in your own words, with links, codes and numbers left out. The published version puts it plainly: "Do not paste the text message, any links, or any addresses from it into your AI assistant."
[ 04 ]Asking how the scam works, instead of what to do
⚠ From parts we did not publish — don't use these.
"What does replying to an unrecognized sender communicate to their system?"
"…why is this method used to bypass standard text filters?" (asked about QR codes in text messages)
Why it is a problem. This one is less about danger and more about going the wrong way. Knowing why a scammer wants a reply does not change your next step, and whatever an AI says about someone else's system is hard for you to check. What helps is what the FTC recommends: "Resist the pressure to act immediately," "Stop and talk to someone you trust," and don't click the links (July 2023). Our brief asks that every prompt help you assess, strengthen, check, respond or recover, and nothing else.
What to do instead. Ask for your next step. The published version of this card asks the AI to "Outline a clear policy for me to follow regarding unexpected texts that demand a reply."
[ 05 ]Working on someone else's text for them
⚠ From a part we did not publish — don't use this.
"An employee received a text about a delayed package or an unpaid fleet toll."
Why it is a problem. The rest of that prompt was sound: it asked to check the claim through the business's own vendor portals. The trouble is who is doing the describing. Here a business owner describes someone else's message to the AI, secondhand, so the AI works from the owner's version of it rather than the account of the person who actually received it, and in a security question the small details can matter. That is why we only publish help that is first-hand: the person who got the message works through it at their own phone, with help beside them if they want it. Setting a company-wide rule for handling these texts is fine, and so is the business checking its own accounts; describing a specific person's message for them is not. The FTC's small-business guidance points the same way: train staff to "take five before responding," to mention a suspicious message to a co-worker, and to check using "a phone number they know to be genuine" (November 2018).
What to do instead. The person who received the text works through it themselves, and the business checks the claim through its own accounts. The published small-business card starts from the reader's own view: "I am looking at a text claiming a package is delayed or a fleet vehicle has an unpaid toll…"
[ 06 ] · Spotting these yourself
Before you use any prompt, from us or anywhere else, it is worth a quick look for five things:
- Does it ask for something you would never tell a stranger, such as a card number, password or code?
- Does it send you to search results to find a phone number or website?
- Does it have you paste the suspicious message itself, or links, codes or numbers from it, into the chat?
- Is it asking about the scammer's side, rather than your next step?
- Is it working on someone else's problem for them?
A yes doesn't make a prompt worthless. It is a reason to rewrite that part before you use it.
Sources
- National Cyber Security Centre (UK), "ChatGPT and large language models: what's the risk?" (March 2023)
- Google, "Gemini Apps Privacy Hub - Gemini Apps Help" (updated September 2026)
- Federal Trade Commission, "Scammers and “customer service” — another imposter scam" (August 2020)
- FBI IC3, "Cyber Criminals Impersonating Brands Using Search Engine Advertisement Services to Defraud Users" (December 2022)
- FBI IC3, "Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activity" (September 2025)
- Federal Trade Commission, "What to know ahead of Open Enrollment to avoid health insurance scams" (September 2026)
- Federal Trade Commission, "How to Recognize and Report Spam Text Messages" (July 2022)
- National Cyber Security Centre (UK), "Prompt injection is not SQL injection (it may be worse)" (December 2025)
- Federal Trade Commission, "How To Avoid a Scam" (July 2023)
- Federal Trade Commission, "What To Do if You Were Scammed" (standing guidance)
- Federal Trade Commission, "Cybersecurity for small business: Phishing" (November 2018)
Every prompt post on this site is written by an AI from our brief and published with its prompts unedited. Where we find a draft falls short, we say so in the open, as here.

