frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Security audit of Browser Use: prompt injection, credential exfil, domain bypass

https://arxiv.org/abs/2505.13076
2•tiny-automates•1h ago

Comments

tiny-automates•1h ago
the planner-executor isolation point is what stood out to me. right now most browser agent frameworks treat the LLM as both the decision-maker and the one processing untrusted content — so a prompt injection in page content can hijack the entire control flow.

the paper's recommendation to split planning (trusted inputs only) from execution (handles untrusted web content) mirrors how we think about privilege separation in OS design, but almost nobody building agent frameworks is actually doing it.

the CVE they found is also telling — Browser Use's domain allowlist could be bypassed, which means the "security" feature was essentially decorative. When you give an agent session tokens and let it navigate freely, the trust boundary problem isn't optional anymore.

Any public labeled dataset of (customer question → seasoned sales response)?

1•StupidoMaximo•23s ago•0 comments

Can you rewire your brain?

https://aeon.co/essays/what-the-metaphor-of-rewiring-gets-wrong-about-neuroplasticity
1•Hooke•4m ago•0 comments

Ask HN: How much did you spend on AI last month?

1•goodthink•5m ago•0 comments

The world is suffering from a shortage of tenors

https://www.economist.com/culture/2026/02/09/the-world-is-suffering-from-a-shortage-of-tenors
1•petethomas•6m ago•0 comments

Show HN: Self-Healing AI Agents with Claude Code as Doctor

https://github.com/Ramsbaby/openclaw-self-healing
2•ramsbaby•8m ago•0 comments

Show HN: Lacune, Go test coverage TUI

https://github.com/alesr/lacune
1•alesrdev•8m ago•0 comments

Pure Go PostgresSQL Parser

https://github.com/ValkDB/postgresparser
1•dhruv_ahuja•9m ago•0 comments

Satya Nadella started following OpenClaw on GitHub

https://mstdn.social/@jukkan/116044854974125204
1•jukkan•10m ago•0 comments

Hello

1•VinWanfan•10m ago•0 comments

Show HN: EverSwarm – Autonomous Recursive Growth Engine (ARGE) for RAG Swarms

1•MikeNathan_ES•15m ago•0 comments

Tailscale Domain Mgmt. Gateway

https://github.com/adrianosela/tsdmg
1•adrianosela•17m ago•1 comments

Seedance 2.0 Is Coming: Full Launch Timeline Revealed

https://www.seedance2.website/ai-video-generator
1•RyanMu•21m ago•1 comments

"Sci-Fi with a Touch of Madness"

https://www.latent.space/p/ainews-sci-fi-with-a-touch-of-madness
1•swyx•22m ago•0 comments

Ask HN: Unflag a Post Gone

1•Ms-J•25m ago•0 comments

The $5M Mistake:How Single Phishing Email Compromised Federal Contractor

https://syncsuptech.substack.com/p/the-5-million-mistake-how-a-single
1•zeddev•27m ago•0 comments

Prompt Contracts – A formal framework for Context Engineering

https://github.com/m3dcodie/prompt-contract
1•m3dcodie_news•27m ago•1 comments

Going Slower Feels Safer, but Your Domain Expertise Won't Save You Anymore [video]

https://www.youtube.com/watch?v=q6p-_W6_VoM
1•kewun•28m ago•0 comments

MCP Knife: A CLI Swiss Army Knife for MCP Servers

https://vivekhaldar.com/articles/mcp-knife-cli-swiss-army-knife-for-mcp-servers/
1•gandalfgeek•30m ago•0 comments

US plans Big Tech carve-out from next wave of chip tariffs

https://www.ft.com/content/e6f7f69a-2552-45f5-ae4c-6f1135e5cde1
4•petethomas•32m ago•0 comments

Show HN: MCP Orchestrator – Spawn parallel AI sub-agents from one prompt

https://github.com/Ask149/orchestrator
2•Ask149•37m ago•0 comments

Show HN: Agx – A Kanban board that runs your AI coding agents

https://github.com/ramarlina/agx
2•Mendrika•39m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
3•Saurabh_Kumar_•39m ago•0 comments

Players discover that World of Warcraft is powered by invisible bunnies

https://www.pcgamer.com/games/world-of-warcraft/players-discover-once-again-that-world-of-warcraf...
2•evo_9•39m ago•0 comments

Why Every Business Must Engage with AI – and How to Do It Right

1•danelrfoster•41m ago•0 comments

Show HN: PicoClaw – lightweight OpenClaw-style AI bot in one Go binary

https://github.com/mosaxiv/picoclaw
2•mosaxiv•46m ago•0 comments

Flood Fill vs. The Magic Circle

https://www.robinsloan.com/winter-garden/magic-circle/
1•gyomu•50m ago•0 comments

Show HN: A CLI tool to automate Git workflows using AI agents

https://github.com/leochiu-a/git-pr-ai
2•leochiu-a•54m ago•0 comments

Use AI to find movies and TV shows on your streaming services

https://pickalready.com
2•hudgeon•55m ago•2 comments

Spec driven development doesn't work if you're too confused to write the spec

https://publish.obsidian.md/deontologician/Posts/Spec-driven+development+doesn%27t+work+if+you%27...
4•habitue•57m ago•0 comments

GenAI Go SDK for AI

https://50984e11.maruel-ca.pages.dev/post/genai-v0.1.0/
1•cpeterso•59m ago•0 comments