Research

Prismata proposes least privilege for web agents

A confinement approach to cross-site prompt injection that constrains both what the agent sees and what it can do, with no per-site annotations.

Cross-site prompt injection is the failure mode that makes browser agents genuinely dangerous rather than merely unreliable: third-party and user-generated content on a page can hijack the agent, and the agent has no reliable way to tell instructions from data.

Prismata's contribution is architectural rather than a better prompt. It applies contextual least privilege — deriving trust dynamically, then mechanically confining the agent by redacting content and restricting capabilities, constraining both what the agent sees and what it can do. The authors report substantially reduced attack success against published web agent attacks, including adaptive variants, while preserving benign task utility, and it requires no developer annotations, so it generalises across sites rather than needing per-site work.

We flag it because the direction matters more than the numbers. Every entry in this directory that drives a browser inherits this problem, and the ones that hold your credentials inherit the worst version of it — a point we make at length in Triaging an inbox. Defences that live in the harness rather than the model are the only kind an integrator can actually deploy.