Prismata: Confining cross-site prompt injection in web agents
Web agents treat third-party page content as instructions, reviving an old attack surface. Prismata dynamically labels page content with permissions, redacts what the agent shouldn't see, and restricts what it can do—no developer annotations needed. It substantially cuts attack success on published web agent attacks while preserving benign task utility. The post doesn't disclose exact numbers or which agents were tested.
Why it matters: Prismata tackles prompt injection in web agents with a classic security-model approach that doesn't require website cooperation—practical and well-scoped. The paper claims significant attack-rate reduction on public benchmarks without degrading normal tasks, making it a notabl...