Skip to content

Discuss general agent ecosystem risks and link to agent security guidance - #334

Open
jpagnucco wants to merge 1 commit into
webmachinelearning:mainfrom
jpagnucco:agent-security-considerations
Open

jpagnucco wants to merge 1 commit into
webmachinelearning:mainfrom
jpagnucco:agent-security-considerations

Conversation

@jpagnucco

@jpagnucco jpagnucco commented Oct 6, 2026 •

Copy link
Copy Markdown

Clarifies in Section 6.2 that general agentic browsing risks (such as indirect prompt injection from untrusted web content and cross-origin data correlation) apply broadly to agents operating on the web and require agent-level security models beyond what a single web API specification can normatively enforce.

Adds an Agent-Level Guardrails and Best Practices subsection in Section 6.4 (Mitigations) noting that agents cannot rely solely on site-asserted tool descriptions or annotations and linking out to external implementation guidance (Agent security considerations for WebMCP and Secure tools with WebMCP), as well as the proposed W3C Agentic Web Working Group Charter where broader cross-ecosystem agent policies and constraints are being explored.

Related to #313.


Preview | Diff

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant