Research · curated 21 Jul 2026
Prismata: Confining Cross-Site Prompt Injection in Web Agents
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Web agents that interpret untrusted page content as instructions are vulnerable to hijacking, and Prismata offers defenders a annotation-free mechanism to bound prompt-injection attacks while maintaining task utility.
Prismata is a research defense for autonomous web agents that confines cross-site prompt injection by enforcing contextual least privilege, using dynamic trust derivation to produce permission labels for page content and mechanical confinement to redact content and restrict agent capabilities. The authors report it substantially reduces attack success across recent published web-agent attacks, including adaptive variants, while preserving benign task utility and requiring no developer annotations.