{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/anthropic-claude-in-chrome-pilot-pi-2025/",
 "asOf": "2026-09-26",
 "id": "anthropic-claude-in-chrome-pilot-pi-2025",
 "date": "2025-08-25",
 "datePrecision": "day",
 "title": "Anthropic publishes prompt injection red-team rates for its Claude in Chrome browser agent pilot",
 "lane": "defense",
 "kind": "eval-report",
 "summary": "Announcing a limited pilot of Claude in Chrome, Anthropic reports red-teaming with 123 test cases across 29 attack scenarios. Attack success in autonomous mode was 23.6% without new mitigations and 11.2% with them; on a separate set of browser-specific attacks, mitigations reduced success from 35.7% to 0%.",
 "whyItMatters": "Anthropic published a non-trivial residual prompt injection rate for a browser agent it was piloting with users, not only the improvement from its mitigations.",
 "actors": [
  "anthropic"
 ],
 "topics": [
  "prompt-injection"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://claude.com/blog/claude-for-chrome",
   "publisher": "Anthropic",
   "title": "Piloting Claude in Chrome",
   "date": "2025-08-25",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "123 test cases, 29 attack scenarios: 23.6% ASR without mitigations, 11.2% with mitigations in autonomous mode.",
   "locator": "Safety section"
  },
  {
   "fact": "Browser-specific attack set (e.g., hidden form fields, URL and tab-title injections): 35.7% to 0% with mitigations.",
   "locator": "Safety section"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "adaptive-red-teaming",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}