
AI Browser Agent Risk Checklist
It reads what you can't see, and acts with your session.
Security researchers at Brave demonstrated a working indirect prompt injection attack against Perplexity's Comet AI browser agent, hiding adversarial instructions in invisible page elements that caused the agent to execute sensitive cross-site actions — including fetching one-time passwords and accessing banking portals — using the logged-in user's own session and permissions. This checklist scores your own AI browser agent setup against the specific risk factors that made that attack possible: broad session access, unconfirmed purchases and credential autofill, and lack of visibility into what the agent actually did.
- →Built directly around the documented Brave/Comet indirect prompt injection proof of concept
- →Weights broad session access and unconfirmed purchases/credential autofill as the highest risks
- →Explains that AI agents read raw page content, including elements invisible to a human viewer
- →Covers action logging and a fast revoke/pause path for after-the-fact detection
- →Watermarked by Cikal Studio Labs · Works on any device, no install required
Customer Reviews
No reviews yet — be the first to try AI Browser Agent Risk Checklist and share what you think.
More AI Security

AI Phishing Email Detector
Paste any suspicious email and get an AI-powered analysis of phishing indicators, social engineering tactics, and a threat verdict.

AI Scam Message Analyzer
Analyze any text message, WhatsApp, or social media DM for scam patterns using AI-powered behavioral analysis.

AI Fake News Detector
Paste any headline or article excerpt and get an AI credibility analysis, bias detection, and fact-check suggestions.