diff --git a/index.bs b/index.bs index da8b99a..0a6e3e6 100644 --- a/index.bs +++ b/index.bs @@ -1315,6 +1315,29 @@ The synthesize a declarative JSON Schema object algorithm, given a <{ "href": "https://arxiv.org/abs/2601.13359", "title": "Sockpuppetting: Jailbreaking LLMs by Combining Prefilling with Optimization", "publisher": "arXiv" + }, + "agenticweb-wg": { + "href": "https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html", + "title": "Agentic Web Working Group Charter", + "publisher": "W3C" + }, + "chrome-agent-security": { + "href": "https://developer.chrome.com/docs/agents/security", + "title": "Agent security considerations for WebMCP", + "authors": [ + "Julia Pagnucco", + "Alexandra Klepper" + ], + "publisher": "Google Chrome Developers" + }, + "chrome-secure-tools": { + "href": "https://developer.chrome.com/docs/ai/webmcp/secure-tools", + "title": "Secure tools with WebMCP", + "authors": [ + "Julia Pagnucco", + "Alexandra Klepper" + ], + "publisher": "Google Chrome Developers" } } @@ -1562,6 +1585,8 @@ This section assumes [=agents=] operate with certain baseline capabilities that These capabilities enable powerful user experiences but also create new risks that must be addressed through a combination of protocol design, agent implementation, and user controls. +Many of the risks associated with these baseline capabilities—such as indirect prompt injection from untrusted web content, cross-origin data correlation, and unauthorized actions within an authenticated session—apply broadly to any [=agent=] operating on the web on a user's behalf, regardless of whether a site exposes WebMCP tools. While WebMCP provides protocol-level boundaries and semantic hints ({{ToolAnnotations/readOnlyHint}}, {{ToolAnnotations/consequentialHint}}, {{ToolAnnotations/untrustedContentHint}}), a malicious site can omit or misrepresent those hints. Preventing an [=agent=] from being manipulated by an untrusted site or inappropriately disclosing cross-origin data is primarily the responsibility of the [=agent=]'s own security model rather than something a single web API specification can normatively enforce. Broader standardization and guidance around [=agent=] permissions, delegation, and web interactions are being explored in the proposed [Agentic Web Working Group](https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html) [[AGENTICWEB-WG]]. +