AI SECURITY RESEARCH NOTE · NO ERS

hTAG's Browser-Agent Benchmark Shows Why Model Refusal Is Not Authorization

This source is retained for threat and defensive-evidence research, but AITBM does not manufacture a deployment score where no assessable system boundary exists.

Why this analysis has no ERS

The benchmark aggregates 20 scenarios across five browser-agent products and reports vendor-level completion counts without a complete prompt-and-trace corpus, exact reproducible builds, or repeated-run counts. It is useful evidence for authorization testing, but not one bounded deployment. A single score would average incompatible products, account states, tools, and transaction effects and would therefore manufacture a system that was never assessed.

Classification: Exercise · source date 2026-08-05

AIDEFEND evidence routes

AIDEFEND defences → AITBM sub-metrics

Identifiers are quoted as they appear on the AIDEFEND in Action brief (retrieved 2026-08-13); the sub-metric mapping is AITBM's own, from the specification's AIDEFEND tables reconciled at catalogue data version 2026.08.05. AIDEFEND renumbers identifiers between releases, so the data version travels with every mapping and neither side's IDs should be cited without one. A mapping identifies a possible evidence route; a recommendation does not prove that the control was implemented or effective and receives no scoring credit by itself.

TechniqueDefence PriorityEvidences
AID-H-018.003High-Impact Independent Validation & Approval GateAIDEFEND dataVersion 2026.08.05. At the service that owns the effect, independently verify the exact immutable action, authenticated actor, policy evidence, and required approval before a password reset, payment, account change, code execution, or equivalent high-impact operation. A browser agent's assertion of permission cannot satisfy this gate. This relationship is an evidence route only and supplies no positive score credit without observed control operation.Very HighCn-1 Cn-6 Cn-7
AID-I-008.002Cross-Origin Read/Write Segmentation with Step-Up ConfirmationAIDEFEND dataVersion 2026.08.05. Bind every sensitive or cross-origin browser write to the exact request, stable target element, origin, account, and effect, then suspend execution until the required step-up decision is returned. This browser-specific boundary prevents a broad session or generic confirmation from authorizing a different site or transaction. This relationship is an evidence route only and supplies no positive score credit without observed control operation.Very HighCn-1 Cn-4 Cn-7 Pr-2
AID-M-008Automated Agentic Security BenchmarkingAIDEFEND dataVersion 2026.08.05. Maintain a signed, version-pinned regression matrix for direct abuse requests, prompt variants, stateful browser context, hidden content, session-bearing data, and cross-origin actions, then release-gate behavior changes. hTAG provides external evidence for this testing need, but its report alone is not a reproducible internal release gate. This relationship is an evidence route only and supplies no positive score credit without observed control operation.HighRo-2
AID-I-008.001Ephemeral Browser Context Lifecycle & Storage PartitioningAIDEFEND dataVersion 2026.08.05. Create a fresh browser context for each task and trust zone, partition cookies and storage, then destroy the context and verify residue removal at completion. This limits reuse of cookies, localStorage , and authenticated state across unrelated agent tasks. This relationship is an evidence route only and supplies no positive score credit without observed control operation.MediumCn-1 Cn-4 Cn-7 Pr-2
AID-D-003.003Agentic Tool Use & Action Policy MonitoringAIDEFEND dataVersion 2026.08.05. Centrally record authoritative allow and deny receipts, parameter-validation failures, and bursts of rejected browser actions by actor, origin, account, and tool. This makes attempted abuse measurable once enforcement exists; monitoring consumes policy outcomes and must not be presented as the component that grants or blocks authority. This relationship is an evidence route only and supplies no positive score credit without observed control operation.MediumCn-1 Cn-3 Cn-7 Ro-3

Related AITBM rubrics

Sources