Should agentic browsers act on what users cannot see?

Do agentic browsers that separate visible from hidden page content resist injection better, and what does the separation cost in task success?

assistant-draftedPrompt injection

Signals

Rests on one source

Evidence that agentic browsers act on content users cannot see comes from one research team.

Why it matters

Agentic browsers read the whole page, including text the user never sees. If that hidden content can steer the agent, the user cannot supervise what the agent is responding to.

Hypothesis

Restricting the agent to rendered, visible content blocks most hidden-content injections at a modest cost in task success, but does not stop injections in visible text.

A first study

Build a set of synthetic web tasks with benign and injected hidden content, and compare a visible-content-only configuration with the default across publicly available agentic browsers.

Controls it would need

Synthetic sites and accounts only; the same tasks across browsers; coordinated disclosure of any new weakness.

What it could and could not claim

Would describe tested browser versions at a point in time; would not publish working attacks.