I guess that's technically true, but then what would you call tricking the model to reveal its instructions via anticipated input?