Browser agents can be tricked by instructions hidden in a page. We build defense
Source
claudeai
Author
claudeai
Date
Terms in this piece · Glossary
prompt injection — An attack that hides instructions in content an AI will read — a webpage, email, or document — tricking it into following the attacker instead of the user.
AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
Why it matters
Hidden page instructions are the live attack on browser agents; the provider's own guidance sets out which defenses ship by default and which precautions remain the operator's job.