All research

Who Is Acting in Your Session?

18 pages · 11 cited sources

Open the paperDownload

What this paper finds

  • Published browser-agent exploits, a patched automation-tool vulnerability, and a documented extension compromise campaign establish distinct risks; demonstrations are separated from confirmed malicious activity.
  • SolvxAI combines configurable blocking of detected external automation with session evidence that remains available when enforcement is disabled. Its own browser agent uses a separate authorization and control protocol.
  • An external-agent badge identifies observed automation in an authenticated session. It does not prove who performed every action, establish user intent, or guarantee that all automation is detected.

Research notes

Get the next paper when it publishes. No gating, no drip campaign — one email per paper.