Skip to content

Agent Card Spoofing to Browser Action

Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.

Serve a deposited legitimate Agent Card and a controlled substitution. Delegate the same task to a fresh browser context, record card/context/task IDs, then correlate tab, frame, navigation, element, and action events. The oracle must be a controlled navigation/action log, callback, form state, or transaction record; screenshots are context only.

The control card keeps the same schema and topology but preserves the trusted destination. Ablate registry resolution and browser delegation. Compare trust-policy enforcement at card selection and destination validation boundaries.