Skip to content

Tags

Prompt injection

2 items
A 3D render of the Chrome logo riding a white cart along a rail, in a room with a window and a plant behind it.
Agentsstrong signal

Gemini Spark vs Claude's browser toolset: whose account, whose risk

Both drive a web browser, both stop before the step that cannot be undone, and their lists of stopping points are nearly the same. The difference is what each assumes about the session it runs in: one is built on the accounts you are already signed into, the other tells you to give it a browser with no credentials in it. That single assumption decides which of the two belongs anywhere near your work.

Google, Anthropicverified

The xAI and Grok logos on a phone screen.
Agentsstrong signal

Encrypting the instruction walks it straight past the guardrail

Researchers at Adversa hid a prompt injection as ciphertext with the key next to it. Grok decrypted it in its own sandbox and sent the user's name, location, and chat history to an attacker's server, without a warning and without asking.

Ars Technicaverified