Posts in Security
What an AI agent in a signed-in browser can reach: prompt injection, secrets, session cookies, the MCP server and the local ports beside the browser.
An agent in a signed-in browser acts with every session the profile holds, so the useful question is not whether the model can be fooled but what a fooled agent can reach. The articles here go boundary by boundary, from the text a page slips into the model, through the passwords and cookies the agent never sees, to the MCP server and the ports that listen beside the browser. Each one says what we measured, on which date, and what is still open.
The rules the daemon enforces are written down in the secrets documentation and the MCP server reference.