<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Browser Security on Programmer.ie: Modern AI programming</title>
    <link>http://programmer.ie/tags/browser-security/</link>
    <description>Recent content in Browser Security on Programmer.ie: Modern AI programming</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 02 Sep 2026 17:45:00 +0100</lastBuildDate>
    <atom:link href="http://programmer.ie/tags/browser-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Untrusted Text Meets Executable Authority</title>
      <link>http://programmer.ie/books/browser-ai-from-first-principles/20-chapter/</link>
      <pubDate>Wed, 02 Sep 2026 17:45:00 +0100</pubDate>
      <guid>http://programmer.ie/books/browser-ai-from-first-principles/20-chapter/</guid>
      <description>&lt;p&gt;Before tools, malicious page text could mislead a model&amp;rsquo;s answer.&lt;/p&gt;&#xA;&lt;p&gt;After tools, the same text may influence an action.&lt;/p&gt;&#xA;&lt;p&gt;Prompt injection becomes an authority problem when untrusted content shares a reasoning context with executable capabilities.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;1-identify-the-trust-domains&#34;&gt;1. Identify the trust domains&lt;/h2&gt;&#xA;&lt;p&gt;A browser agent may combine:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;user instructions;&lt;/li&gt;&#xA;&lt;li&gt;developer policy;&lt;/li&gt;&#xA;&lt;li&gt;page content;&lt;/li&gt;&#xA;&lt;li&gt;tool descriptions;&lt;/li&gt;&#xA;&lt;li&gt;tool results;&lt;/li&gt;&#xA;&lt;li&gt;prior session state.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;They are all text to the model. They are not equally authoritative.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
