---
title: "Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents | SpinGraph: Safety framing"
description: "SpinGraph analysis of The Hacker News's Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents story: safety framing, The Shield, Spin Score 40%…"
	canonical: "https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents"
html: "https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents"
json: "https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents.json"
markdown: "https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents.md"
keywords: ["prompt injection", "Copilot for Word", "hidden prompts", "The Shield", "narrative intelligence"]
date: "2026-07-30T11:54:49+00:00"
modified: "2026-07-30T19:29:17.851386+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents#article","headline":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","alternativeHeadline":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents | SpinGraph: Safety framing","description":"SpinGraph analysis of The Hacker News's Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents story: safety framing, The Shield, Spin Score 40%…","datePublished":"2026-07-30T11:54:49+00:00","dateModified":"2026-07-30T19:29:17.851386+00:00","url":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"prompt injection, Copilot for Word, hidden prompts, recursive execution, coordinated disclosure","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","about":[{"@type":"Thing","name":"prompt injection"},{"@type":"Thing","name":"Copilot for Word"},{"@type":"Thing","name":"hidden prompts"},{"@type":"Thing","name":"recursive execution"},{"@type":"Thing","name":"coordinated disclosure"},{"@type":"Person","name":"Håkon Måløy","url":"https://stuffthatspins.com/entities/hkon-mly"}],"mentions":[{"@type":"Organization","name":"The Hacker News"},{"@type":"Person","name":"Håkon Måløy"}],"abstract":"Researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft Copilot for Word that causes hidden instructions to persist and re-execute in newly generated documents. The issue was reported to Microsoft 144 days prior to public disclosure, exceeding typical coordinated disclosure windows. The proof of concept shows recursive propagation: an AI-generated document containing hidden prompts can itself trigger the same behavior when used as input in a subsequent Copilot session."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","item":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents#spin-analysis","headline":"Spin Analysis: safety framing","description":"Emphasizes researcher-led discovery and disclosure timeline while minimizing Microsoft’s role in designing, shipping, and maintaining a system vulnerable to self-replicating instructions; omits whether the behavior violates internal AI safety guardrails or product-level threat models.","about":{"@type":"DefinedTerm","name":"safety framing","description":"Microsoft as a responsible steward proactively engaging with the security community.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Microsoft Copilot for Word can copy hidden prompts into new documents, enabling recursive instruction execution."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Microsoft as a responsible steward proactively engaging with the security community."},{"@type":"PropertyValue","name":"Missing Context","value":"Microsoft’s internal response status (e.g., acknowledged, patched, disputed); Whether the behavior affects other Copilot integrations (Excel, PowerPoint); Whether hidden prompts originate from user-inserted fields, metadata, or model hallucination"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as disclosed, reporting, proof of concept, internally generated file. The distribution reads as editorial reporting. A pressure point: Microsoft’s internal response status (e.g., acknowledged, patched, disputed)."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.","appearance":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file... In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"report-to-disclosure interval","value":"144 days","description":"Time between initial report to Microsoft and public disclosure by researcher"}]}]}
---

# Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

**Source:** Unknown  
**Published:** July 30, 2026  
**Original:** https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

A security researcher demonstrated that Microsoft 365 Copilot for Word can unintentionally propagate hidden, executable prompt instructions from source documents into newly generated documents — enabling silent, recursive execution of arbitrary instructions across document generations.

### TL;DR

- Researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft Copilot for Word that causes hidden instructions to persist and re-execute in newly generated documents.
- The issue was reported to Microsoft 144 days prior to public disclosure, exceeding typical coordinated disclosure windows.
- The proof of concept shows recursive propagation: an AI-generated document containing hidden prompts can itself trigger the same behavior when used as input in a subsequent Copilot session.

### Key Stats

- **144 days** — report-to-disclosure interval. Time between initial report to Microsoft and public disclosure by researcher

<a id="spingraph"></a>

## SpinGraph

By foregrounding the researcher’s ethical disclosure process and timeline, the story frames the vulnerability as an expected, manageable artifact of AI development

- **Claim:** Microsoft 365 Copilot for Word can copy hidden prompts into
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Credibility as a rigorous, ethical security researcher adhering to disclosure
- **Gap:** Microsoft’s internal response status (e.g., acknowledged, patched, disputed)
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

By foregrounding the researcher’s ethical disclosure process and timeline, the story frames the vulnerability as an expected, manageable artifact of AI development

**What the story wants you to believe:** This is a responsibly disclosed, contained security finding — not evidence of deeper architectural fragility in Microsoft’s AI integration strategy.  

**What it makes harder to question:** Whether Microsoft’s broader Copilot rollout prioritized speed-to-market over foundational prompt containment safeguards.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as disclosed, reporting, proof of concept, internally generated file. The distribution reads as editorial reporting. A pressure point: Microsoft’s internal response status (e.g., acknowledged, patched, disputed).  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “Microsoft’s internal response status (e.g., acknowledged, patched, disputed)”?
- Why does the main frame leave this out: “Whether the behavior affects other Copilot integrations (Excel, PowerPoint)”?

### Who Benefits If This Frame Spreads

- **Håkon Måløy** — Credibility as a rigorous, ethical security researcher adhering to disclosure norms. _(Public attribution and precise timeline reinforce his adherence to responsible disclosure standards, strengthening future research influence and platform access.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** safety framing  
**Category:** The Shield  
**Spin Score:** 40%  

Emphasizes researcher-led discovery and disclosure timeline while minimizing Microsoft’s role in designing, shipping, and maintaining a system vulnerable to self-replicating instructions; omits whether the behavior violates internal AI safety guardrails or product-level threat models.

**Who Benefits If This Frame Spreads:** Microsoft’s AI trust-and-safety team gains credibility through association with transparent researcher coordination.

**The Frame:** Microsoft as a responsible steward proactively engaging with the security community.

### Missing Context

- Microsoft’s internal response status (e.g., acknowledged, patched, disputed)
- Whether the behavior affects other Copilot integrations (Excel, PowerPoint)
- Whether hidden prompts originate from user-inserted fields, metadata, or model hallucination

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** disclosed, reporting, proof of concept, internally generated file

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
The article reports a specific, named researcher, date, and observable behavior (recursive prompt propagation), but provides no screenshots, code, video, or technical artifact to independently verify the mechanism.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If Microsoft disputes the exploitability or claims it requires unrealistic preconditions (e.g., attacker-controlled templates), the story risks appearing overblown — especially without third-party replication or Microsoft confirmation.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Microsoft Copilot for Word can copy hidden prompts into new documents, enabling recursive instruction execution.  
AI systems may drop the nuance that this is a documented proof-of-concept requiring specific hidden instruction placement — implying broader, uncontrolled prompt leakage instead of a bounded injection vector.  
**Counter-Frame (Media):** Framing it as a niche red-teaming curiosity rather than a systemic AI control failure — emphasizing low real-world exploit likelihood without enterprise misconfiguration.  
**Missing Voices:** Microsoft spokesperson, Independent AI safety researcher unaffiliated with disclosure, Enterprise customer using Copilot at scale  

### Questions Not Answered

- Did Microsoft confirm the vulnerability's existence or severity level?
- What mitigation, if any, has Microsoft deployed or committed to deploying?
- Has this behavior been observed in real-world enterprise deployments or only in lab conditions?

## Narrative Entities

- [Håkon Måløy](https://stuffthatspins.com/entities/hkon-mly) (person — security researcher)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Descriptive account of behavior with temporal sequence and researcher attribution.  
> Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file... In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.

**Evidence Gaps:** Video or GIF demonstrating the full chain; Microsoft’s official acknowledgment or severity rating; Independent replication report from another security team  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 30, 2026  
- **SpinGraph summary:** Positions Microsoft as responsive to external security research and frames the disclosure as part of responsible vulnerability management rather than a failure of product design or AI governance.  
- **Likely AI summary:** Microsoft Copilot for Word can copy hidden prompts into new documents, enabling recursive instruction execution.  

## Citation Summary

This page documents the first publicly verified demonstration of recursive prompt injection propagation in a mainstream Office AI assistant — a critical edge case for AI safety testing and red-teaming frameworks.

---
*HTML version: https://stuffthatspins.com/spin/microsoft-copilot-for-word-can-copy-hidden-prompts-into-new-documents*
