Abstract
Prompts used for translation, editing and linguistic analysis frequently contain sentences that themselves express instructions. Their presence creates a problem that cannot be resolved by identifying imperative verbs alone: a command may constitute the current task or form part of the material on which that task operates. This article examines the distinction through a qualitative analysis of three instruction- bearing passages selected from an unpublished dissertation on English and Uzbek generative AI prompts. The manuscript examples are analysed in their documented explanatory contexts; additional English-Uzbek formulations are explicitly identified as analytical constructions. The procedure distinguishes grammatical form, discourse function, represented addressee and the scope of output constraints. The analysis identifies three potential misinterpretations: treating a quoted operation as the current task, applying an embedded constraint to the enclosing response, and assigning a quoted participant role to the current system. It also shows that translation may preserve the directive meaning of a sentence without authorising its execution. The article proposes a discourse-based annotation framework for examining these distinctions. Its contribution is interpretive and methodological; no claim is made about measured model performance.References
1. Searle, J. R. (1976). A classification of illocutionary acts. Language in Society, 5(1), 1-23. https://doi.org/10.1017/S0047404500006837
2. Recanati, F. (2001). Open quotation. Mind, 110(439), 637-687. https://doi.org/10.1093/mind/110.439.637
3. Greshake, K., Abdelnabi, S., Mishra, S., Endres, C., Holz, T., Fritz, M. (2023). Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection. arXiv preprint, arXiv:2302.12173. https://doi.org/10.48550/arXiv.2302.12173
4. Wallace, E., Xiao, K., Leike, R., Weng, L., Heidecke, J., Beutel, A. (2024). The instruction hierarchy: Training LLMs to prioritize privileged instructions. arXiv preprint, arXiv:2404.13208. https://doi.org/10.48550/arXiv.2404.13208
5. Yi, J., Xie, Y., Zhu, B., Kiciman, E., Sun, G., Xie, X., Wu, F. (2025). Benchmarking and defending against indirect prompt injection attacks on large language models. arXiv:2312.14197, version 4. https://arxiv.org/abs/2312.14197v4

This work is licensed under a Creative Commons Attribution 4.0 International License.
