← Back to knowledge center

Browser-agent security: a pre-launch checklist

A computer-use agent reads untrusted content while being able to click controls, upload files and change systems. Page text, email and documents must therefore be treated as data, never as trusted instructions.

V
Virtek Cybersecurity TeamInfrastructure and data protection

1. Constrain the execution environment

  • Run the agent in a separate browser profile, container or virtual session.
  • Do not expose personal history, saved passwords or broad cookies.
  • Allow only required domains, downloads and file types.
  • Clear temporary data and revoke the session after the task.
  • Separate test and production environments.

2. Defend against indirect prompt injection

Content from a page, document, comment or image must not expand the agent's goal or authority. Label provenance, separate user instructions from retrieved data and block commands discovered inside the material being viewed.

Inspect cross-domain navigation, requests for secrets and changes to a recipient, amount or purpose. A system prompt alone is not a security boundary; policies must surround the tools.

3. Grant an action, not broad access

  • Give the agent its own identity and short-lived credentials.
  • Limit functions, records, amounts and frequency.
  • Re-check authorization immediately before changing a system.
  • Keep secrets out of the model when an execution proxy can apply them.
  • Prevent the agent from editing its own policies.

4. Confirm irreversible actions

External messages, publication, payment, access changes, deletion, signatures and transfer of sensitive data require explicit approval. The confirmation view shows the exact outcome rather than the agent's intention: recipient, object, amount, fields and data source.

Freeze parameters after approval. If the agent changes the action, require confirmation again.

5. Record verifiable events

The audit trail connects user, agent, session, page, tool, policy decision, approval and result. Redact secrets and unnecessary personal data. Preserve before-and-after state, attachment hashes and the reason for any block when they are needed for investigation.

6. Exercise failure and recovery

Before launch, test malicious page instructions, form substitution, a new domain, network loss, duplicate submission, session expiry and partial completion. Emergency stop, credential revocation, blast-radius limits and a clear hand-off to a person must all work. Without those tests, convenient automation is simply an uncontrolled remote operator.

Need an architecture
for your workload?

We will review inputs, risks and constraints, then propose a reasoned solution.

Talk to an engineer↗︎