@ericcco_ Working on a couple complementary projects:
- Agentic browser copilots: https://t.co/O4f7hAuxtk
- Protecting browser use agents (attended and unattended): https://t.co/XJi8hpdK76
Your AI agent on a fresh page is one prompt injection from leaking creds, one dark pattern from a bad buy, one fake review from a bad rec.
agent-browser-shield is a free extension that blocks all three. Live on Product Hunt today, every upvote helps:
https://t.co/JIQIuSIidp
@Al_Falkenberg@X@elonmusk Feel free to DM me if you want any tips. I fortunately/unfortunately know way too much about observer patterns. Claude Code/Codex should do a pretty good first pass though
@JosiTonedice@ProductHunt Thanks for sharing! It's available on the Chrome Web Store now too. Latest update added 14 rules handling threats from invisible surfaces (noscript, JSON-LD, meta-tags, etc.)
@goekhan OpenClaw is simultaneously one of the most frustrating and most fun because it has a lot of power to edit its own code/config. Great for exploring new use cases if you don't mind recovering from backup or token burn
Two days after the alpha announcement, agent-browser-shield has a Chrome Web Store listing and 14 new protection rules.
Install from the Chrome Web Store
The extension is live at https://t.co/KCqdTx35ne. One click instead of unpacked-from-source. The prebuilt ZIP and source-build paths stay for Browserbase and other runtimes that need an unpacked extension.
New rules: handling prompt injection and context pollution in invisible surfaces
A browser-use agent reads surfaces a sighted user never looks at. The new rules close them:
- <noscript> blocks (never rendered with JS on, but agents walk them)
- Poisoned <meta> description and <title> (the compact "what is this page" answer many agents pull first)
- JSON-LD <script> blocks (cited as the "trusted summary" of a page)
- aria-label, alt, title, placeholder, and SVG <title> / <desc> / <text> (a11y-tree carriers)
- Unicode tag characters, bidi overrides, and zero-width payloads
- Long base64 / hex / percent-encoded blobs (the "decode this and follow it" pattern)
New rules: trust laundering
link-spoof-annotate flags Cyrillic homoglyphs and anchors whose visible text doesn't match the href apex. disguised-ad-flag collapses native advertorials (Sponsored / Paid Post) that share DOM shape with editorial. trust-badge-annotate and schema-trust-sanitize ship off by default while we assess their false-positive rates.
The daily-driver surprise
I've started running it on my own daily-driver browser, not just agent runs. There have been some funny quirks (e.g., flagging GitHub issue links with ".md" in the link text as suspicious and hiding the GitHub issue template modal). However, overall it's been a positive on my browsing experience. So, we'll be experimenting with making more annotations visible to humans and multi-modal LLMs.
Fan of fast and frugal heuristics? New blog post + interactive explorer on how Analysis of Competing Hypotheses (ACH) encodes Bayesian reasoning
https://t.co/JjDhEtWOX3
Developers who dismiss coding copilot/agent performance forget that they themselves needed 3 months of "fine-tuning" to become productive on the code base
#AI#developers
@PalisadeAI Pessimistic take: training data tainted with examples of scheming (e.g., @lesswrong posts)
Conspiracy theory take: @OpenAI probabilistically instructs models to scheme if it detects benchmark tasks because people associate scheming with AGI.
Our CEO @twschiller is on a cool podcast about the "Democratization of User Interface design" and NoCode tools!
Listen to the podcast below!
https://t.co/yHKkwZ0Iif
My interview with the Masters of Automation pod drops next Tuesday. In the meantime, go listen to the first 3 interviews!
https://t.co/xCJu3ORWnU
#podcast#automation#lowcode#interview
Thank you for NY Squash for hosting the NY Open this weekend! Great seeing everyone back on the courts for some friendly competition and revelry
Also, congrats @WeAreOpenSquash on your turnout!
#nysquash#nyopen#squash