Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions index.bs
Original file line number Diff line number Diff line change
Expand Up @@ -1315,6 +1315,29 @@ The <dfn>synthesize a declarative JSON Schema object algorithm</dfn>, given a <{
"href": "https://arxiv.org/abs/2601.13359",
"title": "Sockpuppetting: Jailbreaking LLMs by Combining Prefilling with Optimization",
"publisher": "arXiv"
},
"agenticweb-wg": {
"href": "https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html",
"title": "Agentic Web Working Group Charter",
"publisher": "W3C"
},
"chrome-agent-security": {
"href": "https://developer.chrome.com/docs/agents/security",
"title": "Agent security considerations for WebMCP",
"authors": [
"Julia Pagnucco",
"Alexandra Klepper"
],
"publisher": "Google Chrome Developers"
},
"chrome-secure-tools": {
"href": "https://developer.chrome.com/docs/ai/webmcp/secure-tools",
"title": "Secure tools with WebMCP",
"authors": [
"Julia Pagnucco",
"Alexandra Klepper"
],
"publisher": "Google Chrome Developers"
}
}
</pre>
Expand Down Expand Up @@ -1562,6 +1585,8 @@ This section assumes [=agents=] operate with certain baseline capabilities that

These capabilities enable powerful user experiences but also create new risks that must be addressed through a combination of protocol design, agent implementation, and user controls.

Many of the risks associated with these baseline capabilities—such as indirect prompt injection from untrusted web content, cross-origin data correlation, and unauthorized actions within an authenticated session—apply broadly to any [=agent=] operating on the web on a user's behalf, regardless of whether a site exposes WebMCP tools. While WebMCP provides protocol-level boundaries and semantic hints ({{ToolAnnotations/readOnlyHint}}, {{ToolAnnotations/consequentialHint}}, {{ToolAnnotations/untrustedContentHint}}), a malicious site can omit or misrepresent those hints. Preventing an [=agent=] from being manipulated by an untrusted site or inappropriately disclosing cross-origin data is primarily the responsibility of the [=agent=]'s own security model rather than something a single web API specification can normatively enforce. Broader standardization and guidance around [=agent=] permissions, delegation, and web interactions are being explored in the proposed [Agentic Web Working Group](https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html) [[AGENTICWEB-WG]].

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you wrap this (possibly using the https://github.com/domfarolino/specfmt crate) to 100 characters per line? Some of the pre-existing lines in the spec predate that formatting requirement which I should fix separately. But if we could break this up to match all of the new stuff that'd be great! If you see the stack of comments below, and note how they're not anchored to the line that they concern, you'll see why we have the column length guideline.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's start a new paragraph starting with "Preventing an [=agent=] [...]"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's replace "a single web API specification" with "this specification". Because who knows, maybe we'll come up with a single "secure web agent harness" specification 🤷‍♂️ .

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's add "identity" to the list of things the agentic WG is handling.


<h3 id="key-risks">Key Security and Privacy Risks</h3>

<h4 id="prompt-injection">Prompt Injection Attacks</h4>
Expand Down Expand Up @@ -1929,6 +1954,14 @@ page, protecting against malicious scripts or dependencies from using WebMCP API

**How:** A boolean {{ToolAnnotations/consequentialHint}} annotation acts as a signal to the client or agent that the tool performs a consequential action, such as booking a flight or transferring money. This way they can selectively enforce mandatory user confirmation prompts before executing high-stakes tools, directly mitigating the risk of accidental or malicious misrepresentation of intent.

<h4 id="mitigation-agent-level-guardrails">Agent-Level Guardrails and Best Practices</h4>

**What:** Deterministic and probabilistic guardrails enforced by the [=agent=] or [=user agent=] harness when consuming WebMCP tools.

**Threats addressed:** [[#prompt-injection]], [[#misrepresentation-of-intent]], [[#privacy-leakage-over-parameterization]]

**How:** Because websites registering WebMCP tools may themselves be untrusted or compromised, [=agents=] cannot rely solely on site-asserted tool descriptions or annotations for security. Defining the architecture of a secure browser-use [=agent=] is outside the scope of this specification; however, [=agent=] implementers are strongly encouraged to implement defense-in-depth guardrails. For external implementation guidance on securing [=agents=] and tools that use WebMCP, see [[CHROME-AGENT-SECURITY]] and [[CHROME-SECURE-TOOLS]]. Broader cross-ecosystem discussions on expressing policies, constraints, and guidance for [=agent=] interactions on the web are also underway in the proposed [Agentic Web Working Group](https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html) [[AGENTICWEB-WG]].

<h2 id="accessibility">Accessibility considerations</h2>


Expand Down
Loading