Research · curated 21 Jul 2026

Prismata: Confining Cross-Site Prompt Injection in Web Agents

Coverage timeline

10 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Web agents that interpret untrusted page content as instructions are vulnerable to hijacking, and Prismata offers defenders a annotation-free mechanism to bound prompt-injection attacks while maintaining task utility.

Prismata is a research defense for autonomous web agents that confines cross-site prompt injection by enforcing contextual least privilege, using dynamic trust derivation to produce permission labels for page content and mechanical confinement to redact content and restrict agent capabilities. The authors report it substantially reduces attack success across recent published web-agent attacks, including adaptive variants, while preserving benign task utility and requiring no developer annotations.