Research · curated 25 Aug 2026
Measuring Indirect Prompt Injection in Autonomous Web Agents by Sahir Maharaj :: SSRN
First reported ssrn.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
WIPI gives defenders a structured way to measure indirect prompt injection risk in autonomous web agents, which collapse the data/authority boundary browsers spent decades enforcing and can be steered to invoke tools, cross origins, and exfiltrate private context.
The paper 'Measuring Indirect Prompt Injection in Autonomous Web Agents' by Sahir Maharaj introduces WIPI, a deployment-oriented measurement protocol for Web Indirect Prompt Injection that separates exposure, instruction uptake, harmful action, attacker-goal completion, concealment, recovery, benign utility, and overblocking. It synthesizes academic benchmarks (e.g., WASP), browser-security studies, standards, and red-team evidence, arguing that even low model-level attack-success rates do not equate to a trustworthy web agent and that security must be enforced architecturally through provenance, instruction hierarchy, capability separation, and information-flow control.