AIagent securityStory 01
Nine of 15 agent approval designs were forgeable
What changedResearchers tested 15 ways for an AI agent to ask for confirmation and found that nine could be forged. Their core lesson is simple: approval evidence cannot live in the same place an agent or hostile page is allowed to rewrite.

The useful part
Why it matters
A visible approved message is not a security boundary if the agent or hostile content can write the same surface; approval evidence needs an isolated trusted channel.
Keep in mind
Good to know
This is a controlled study, not proof that every similar-looking product is exploitable. The useful finding is the trust boundary: moving evidence off an attacker-writable channel cut attack success from 97% to zero in one tested setting.
Evidence