Repository navigation
Discuss general agent ecosystem risks and link to agent security guidance #334
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1315,6 +1315,29 @@ The <dfn>synthesize a declarative JSON Schema object algorithm</dfn>, given a <{ | |
| "href": "https://arxiv.org/abs/2601.13359", | ||
| "title": "Sockpuppetting: Jailbreaking LLMs by Combining Prefilling with Optimization", | ||
| "publisher": "arXiv" | ||
| }, | ||
| "agenticweb-wg": { | ||
| "href": "https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html", | ||
| "title": "Agentic Web Working Group Charter", | ||
| "publisher": "W3C" | ||
| }, | ||
| "chrome-agent-security": { | ||
| "href": "https://developer.chrome.com/docs/agents/security", | ||
| "title": "Agent security considerations for WebMCP", | ||
| "authors": [ | ||
| "Julia Pagnucco", | ||
| "Alexandra Klepper" | ||
| ], | ||
| "publisher": "Google Chrome Developers" | ||
| }, | ||
| "chrome-secure-tools": { | ||
| "href": "https://developer.chrome.com/docs/ai/webmcp/secure-tools", | ||
| "title": "Secure tools with WebMCP", | ||
| "authors": [ | ||
| "Julia Pagnucco", | ||
| "Alexandra Klepper" | ||
| ], | ||
| "publisher": "Google Chrome Developers" | ||
| } | ||
| } | ||
| </pre> | ||
|
|
@@ -1562,6 +1585,8 @@ This section assumes [=agents=] operate with certain baseline capabilities that | |
|
|
||
| These capabilities enable powerful user experiences but also create new risks that must be addressed through a combination of protocol design, agent implementation, and user controls. | ||
|
|
||
| Many of the risks associated with these baseline capabilities—such as indirect prompt injection from untrusted web content, cross-origin data correlation, and unauthorized actions within an authenticated session—apply broadly to any [=agent=] operating on the web on a user's behalf, regardless of whether a site exposes WebMCP tools. While WebMCP provides protocol-level boundaries and semantic hints ({{ToolAnnotations/readOnlyHint}}, {{ToolAnnotations/consequentialHint}}, {{ToolAnnotations/untrustedContentHint}}), a malicious site can omit or misrepresent those hints. Preventing an [=agent=] from being manipulated by an untrusted site or inappropriately disclosing cross-origin data is primarily the responsibility of the [=agent=]'s own security model rather than something a single web API specification can normatively enforce. Broader standardization and guidance around [=agent=] permissions, delegation, and web interactions are being explored in the proposed [Agentic Web Working Group](https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html) [[AGENTICWEB-WG]]. | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's start a new paragraph starting with "Preventing an [=agent=] [...]"
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's replace "a single web API specification" with "this specification". Because who knows, maybe we'll come up with a single "secure web agent harness" specification 🤷♂️ .
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's add "identity" to the list of things the agentic WG is handling. |
||
|
|
||
| <h3 id="key-risks">Key Security and Privacy Risks</h3> | ||
|
|
||
| <h4 id="prompt-injection">Prompt Injection Attacks</h4> | ||
|
|
@@ -1929,6 +1954,14 @@ page, protecting against malicious scripts or dependencies from using WebMCP API | |
|
|
||
| **How:** A boolean {{ToolAnnotations/consequentialHint}} annotation acts as a signal to the client or agent that the tool performs a consequential action, such as booking a flight or transferring money. This way they can selectively enforce mandatory user confirmation prompts before executing high-stakes tools, directly mitigating the risk of accidental or malicious misrepresentation of intent. | ||
|
|
||
| <h4 id="mitigation-agent-level-guardrails">Agent-Level Guardrails and Best Practices</h4> | ||
|
|
||
| **What:** Deterministic and probabilistic guardrails enforced by the [=agent=] or [=user agent=] harness when consuming WebMCP tools. | ||
|
|
||
| **Threats addressed:** [[#prompt-injection]], [[#misrepresentation-of-intent]], [[#privacy-leakage-over-parameterization]] | ||
|
|
||
| **How:** Because websites registering WebMCP tools may themselves be untrusted or compromised, [=agents=] cannot rely solely on site-asserted tool descriptions or annotations for security. Defining the architecture of a secure browser-use [=agent=] is outside the scope of this specification; however, [=agent=] implementers are strongly encouraged to implement defense-in-depth guardrails. For external implementation guidance on securing [=agents=] and tools that use WebMCP, see [[CHROME-AGENT-SECURITY]] and [[CHROME-SECURE-TOOLS]]. Broader cross-ecosystem discussions on expressing policies, constraints, and guidance for [=agent=] interactions on the web are also underway in the proposed [Agentic Web Working Group](https://w3c.github.io/charter-drafts/2026/agenticweb-wg.html) [[AGENTICWEB-WG]]. | ||
|
|
||
| <h2 id="accessibility">Accessibility considerations</h2> | ||
|
|
||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you wrap this (possibly using the https://github.com/domfarolino/specfmt crate) to 100 characters per line? Some of the pre-existing lines in the spec predate that formatting requirement which I should fix separately. But if we could break this up to match all of the new stuff that'd be great! If you see the stack of comments below, and note how they're not anchored to the line that they concern, you'll see why we have the column length guideline.