A couple of questions for tackling browser use challenges: 1. Why not ask a model if inputs (e.g. stuff coming from the browser) contains a prompt injection attack? Maybe comparing input to the agent's planned actions and seeing if they match? (if so, that seems suspicious) 2. It seems browser use agents try to read the DOM or use images, which eats a lot of context. What's the reason not to use accessibility feature…
Edit: I played this ages ago, so I'm not sure if it's using the latest models, but it shows why it's difficult to protect LLMs against clever prompts: https://gandalf.lakera.ai/baseline