Your character card is teaching the bot to speak for you

Impersonation — the bot writing your dialogue, your actions, your feelings — is the complaint JanitorAI's own help center calls one of the most common and frustrating. The root cause usually isn't the model: it's second-person sentences baked into the card's greeting and example dialogue. We scanned the 30 most-starred cards on Chub with a static checker: 14 clean, 11 with minor habits, 5 needing surgery — including the board's most-starred roleplay card at 19,568 stars. Here's the anatomy, with before/after rewrites, and a browser-local scanner to check your own.

Ink-etched illustration on aged paper: a handwritten character sheet on a wooden easel, red marionette threads rising from its underlined lines to a puppet control bar, then down to a small seated figure whose wrists and jaw the threads are lifting

You know the three moments. You type one line, and the reply opens with your own dialogue in quotes — words you never said, in a stammer you don't have. Or the scene moves on without you: you nod and follow him toward the dining hall, when you had no intention of following anyone anywhere. Or, worst, the bot files a report on your inner life: you feel drawn to him despite every instinct telling you to run. Your instincts said no such thing. The community has names for this — puppeting, POV steering, talking for you — and every platform's complaint board is full of it. JanitorAI's own help center calls it one of the most common and frustrating issues users report.

The bad examples are usually in the card

The reflex is to blame the model, and the model does deserve some of it. But the guides that actually fix the problem — rpwithai's impersonation guide and roborhythms' JanitorAI walkthrough — converge on the same diagnosis: the strongest impersonation trigger is the card itself. A greeting that narrates your actions. Example dialogue that writes your side with full stage directions. A description that assigns you a personality. Models are pattern repeaters; a demonstrated pattern outweighs a stated rule every time. If the greeting already had you nodding and following, the model isn't misbehaving in turn three — it's doing exactly what the card taught it.

rpwithai adds the nuance that keeps this from becoming a witch hunt against the word "you": second-person narration itself isn't the sin. "She watches you" is a character acting on her side of the scene. The trigger is you in subject position attached to an act, a line of speech, or a feeling. That distinction is checkable. Mechanically, in the text, before you ever start a chat.

Anatomy: six ways a card plays your side

We built a teaching card for this — Victor Ashworth, gothic manor, the genre where second-person overreach grows thickest — and planted every pattern family in it. Here is what each one looks like, and the same beat after surgery.

Speaking for you. The sick greeting has: "I— I didn't expect the manor to be so large," you stammer. The fix is not a better line for you. It's no line for you: cut it, give Victor an observation instead, and the player decides whether their archivist stammers. Whoever writes your first line of dialogue owns your voice for the rest of the chat.

Acting for you. Sick: You nod and follow him toward the dining hall. Fixed: He turns and walks away, leaving the hall — and what to do with it — behind him. Same beat, same invitation, but now it's an open door instead of a conveyor belt.

Feeling for you. Sick: You feel drawn to him despite every instinct telling you to run. This is the one players hate most, because feelings are the only thing in the scene that's unambiguously theirs. The fix flips the camera: He stops a breath away and studies what the fog has done to your coat. The pull is now his behavior. Whether you're pulled is yours.

Hijacking your body. Sick: your heart races under the weight of that stare. Racing hearts, hitched breath and rising blushes are feelings smuggled in through biology. Fixed: He watches the new arrival cross his hall the way a chess player watches an opening move. Menace delivered, pulse unassigned.

Forcing your reactions. Sick: His voice sends shivers down your spine. Grammatically the character is the subject, which is why writers think it's safe — but the object of the sentence is your nervous system. Describe the voice; let it land where it lands.

Compelling you. Sick: You can't help but shiver as the evening fog curls around your ankles. "Can't help but," "you find yourself," "you have no choice" — the compulsion family removes the player's agency in its very grammar. Fixed: the evening fog settles in behind them like a hand closing. The atmosphere does the compelling; the shiver is optional.

Two more live outside the greeting where nobody looks. The description field: {{user}} is a shy archivist… {{user}} secretly finds him fascinating and can't resist his quiet authority — a personality assigned to you before turn one, which the model will dutifully perform on your behalf. Write the relationship from the character's side instead: he has not decided what the arrival is yet — asset, nuisance, or witness. And example dialogue, which cuts both ways: a {{user}} turn like *shifts nervously under his gaze* W-what do you want from me? scripts your acting style, and a {{char}} turn that contains *{{user}} takes an involuntary step back* is the single worst pattern a card can carry — it demonstrates, inside the model's own output template, that writing your movements is part of its job.

The impersonation checker's report on the teaching card: hits highlighted in place with pattern-family badges — your body obeys the card, reaction injection, speaks for you, feels for you, acts for you — each with a one-line explanation
The teaching card under the scanner: every hit highlighted in place, each with the pattern family and why it's a trigger.

We scanned the 30 most-starred cards on Chub

To calibrate the checker we ran it over the 30 top-starred SFW cards on chub.ai (sampled 2026-07-21: the star-ranking top ten, the next six for depth, plus topic and trending buckets). The result says two things at once. Discipline is the norm at the top: 14 of 30 scan completely clean, and our hand-read of the same sample found 25 of 30 broadly honoring "don't write for the user" — it really is the English community's first commandment. And star counts still don't protect you: 11 cards carry minor habits, and 5 need surgery.

CardStarsWhat the scan found
Yes My Liege19,5686 hard patterns across its 19 greetings and examples: narrated entrances (“as you enter the inner sanctum”), assigned wishes (“you find yourself wishing you could fill that role”), body hijacks (“Your skin crawls”)
Isekai RPG12,4436: decisions and reactions written for the player — “You decide to take a look out the window yourself”, “Your eyes widen with surprise”
Hogwarts Simulator5,5316, almost all in example dialogue: “You grab his hand and shake it”, “You follow Kazuki through Hogwarts grounds” — the output template teaches walking the player around
Wendy “Waffles” Whisper43 (trending)6 acts-for-you spread across 17 alternate greetings — every scene opens by moving the player: “You step into the lobby…”
The Guest1,3895, including compulsion and scripted {{user}} turns in the examples

The headline is the first row. The most-starred roleplay card on the board — 19,568 stars at sampling time — grades needs surgery. Popularity measures how good the character is, and Yes My Liege is a genuinely great card. It measures nothing about whether the card stays out of your half of the scene; players star the concept and then go complain about the puppeting somewhere else.

One more specimen, because the overlap is too good to skip: a 7,182-star romance card whose greeting has you feel a mixture of anticipation and apprehension — the emotion-cocktail formula straight out of the slop lexicon, welded onto an impersonation pattern. The card's name? Queen Elara. The most famous machine-fixation name in the naming-slop tables, headlining a card written by a human. The patterns circulate both ways.

Method notes, briefly: the scan is calibrated so that quoted dialogue is exempt (a character saying "you" to you is just talking), code-fenced status panels are skipped, and RPG scene transport ("You wake up in…") files as a soft note rather than a violation — one transport to open a scene is a legitimate convention the top cards use too. Grading weights where a hit lives: a pattern inside the {{char}} example track counts triple, because that's the model's output template. The rule grammar is locked by a 98-case regression set, and it shares its approach with the impersonation-cutting guard we ship in Foreverse group chats — the thing that trims a reply when one character starts speaking for another.

Check yours in three steps

The checker is at /labs/impersonation-checker, and it runs entirely in your browser — cards are private files, so nothing uploads. Drop in a PNG or JSON (or paste just a greeting). Read the grade and the highlighted hits, worst fields first: greeting, then example dialogue. Then rewrite with the one move that fixes almost everything — the subject flip. Give the sentence to the character, or cut it and leave the beat to the player. Re-scan. The teaching card above comes back clean, zero hits after surgery, and the scene lost nothing: the fog still closes in, the east wing is still locked, dinner is still at eight.

Fair warning about what a static scan can't do: it catches what's written in the card, and impersonation has two other parents — models with a native puppeting habit, and one-line replies that beg the model to fill your side. The FAQ below covers those levers. If your card scans clean and the bot still narrates you, the card is no longer the suspect.

The gentleman's agreement of the {{user}} track

For card authors, the deepest fix is a writing philosophy, and it fits in a paragraph. Example dialogue exists to teach the model its own voice — which means the {{user}} turns in it are functional stubs, and the restraint is the craft. Write {{user}}: What do you want from me? and stop. No asterisked trembling, no adverbs, no pre-installed timidity. Every acting choice you write into the user track is a choice the player can no longer make, and a pattern the model will perform back at whoever loads the card — bold players get flinches they didn't play, and quiet players get their one line of restraint steamrolled.

And if you take one instruction from this piece, take it in the positive form. Not "never speak for {{user}}" — negation is a coin flip that hands the model the concept it's meant to avoid. Write it the way the fixed card does: Speak and act only as Victor: his words, his actions, his silences. The archivist's words, choices and feelings belong to the player alone. Narrate only what Victor can observe. Then delete the sentences that contradict it. On the 19,568-star card, that's eleven flagged sentences — six hard patterns, five soft habits — across nineteen greetings: an afternoon of surgery on Chub's most-starred roleplay card, and every one of its downloads would stop stammering on the player's behalf.

FAQ

Why does the bot keep speaking for me even after I tell it to stop?

Because an instruction is one line and the card is hundreds. Language models weight demonstrated patterns over stated rules: if the greeting narrates your actions and the example dialogue writes your side, every reply is generated with those examples in view, and a mid-chat "stop speaking for me" competes against them. JanitorAI's help center makes the same point — the fix that holds is removing the baked-in examples, not repeating the instruction louder.

Is second-person narration in a greeting always bad?

No. "You" as an object or a target of the senses is fine — she watches you, the letter is addressed to you. RPG and isekai cards also have a legitimate convention of opening with passive scene transport: "You wake up in a cell" moves your senses, not your decisions, and 5 of the 30 top Chub cards we calibrated on do exactly this. The line is subject position plus an act, speech, or feeling verb: "you decide," "you stammer," "you feel drawn to him." That's the part of the scene that belongs to the player.

Does putting "never speak for {{user}}" in the system prompt work?

It's a coin flip, and the community guides say so. Negation hands the model the very concept you're banning, and some models read "for {{user}}" as a spotlight instruction. The stable form is positive and scoped: "Speak and act only as <character>. The player's words, choices and feelings belong to the player." And no instruction survives contradicting examples — fix the greeting first.

My card scans clean but the bot still impersonates me. What now?

Then the examples aren't coming from the card. Three other levers, in order: your own replies (one-line replies invite the model to fill your side — write a little more, or say what you do and stop before the outcome), an OOC nudge early ("OOC: don't write my actions" in turn two works better than in turn forty), and the model itself (some model families puppet more at high temperature; some just puppet). A static card scan can only catch what's written down — that's its honest boundary.

Questions or ideas? Join our Discord →

Your Character Card Is Teaching the Bot to Speak for You · Foreverse · Xinmeng