Skip to content
Hacker News front page

Prismata: Confining cross-site prompt injection in web agents

Web agents treat third-party page content as instructions, reviving an old attack surface. Prismata dynamically labels page content with permissions, redacts what the agent shouldn't see, and restricts what it can do—no developer annotations needed. It substantially cuts attack success on published web agent attacks while preserving benign task utility. The post doesn't disclose exact numbers or which agents were tested.

Why it matters: Prismata tackles prompt injection in web agents with a classic security-model approach that doesn't require website cooperation—practical and well-scoped. The paper claims significant attack-rate reduction on public benchmarks without degrading normal tasks, making it a notabl...

Read the original ↗Export Markdown