Building Browser Agents: Architecture, Security, and Practical Solutions
By: Aram Vardanyan
Potential Business Impact:
Makes web robots safer and more helpful.
Browser agents enable autonomous web interaction but face critical reliability and security challenges in production. This paper presents findings from building and operating a production browser agent. The analysis examines where current approaches fail and what prevents safe autonomous operation. The fundamental insight: model capability does not limit agent performance; architectural decisions determine success or failure. Security analysis of real-world incidents reveals prompt injection attacks make general-purpose autonomous operation fundamentally unsafe. The paper argues against developing general browsing intelligence in favor of specialized tools with programmatic constraints, where safety boundaries are enforced through code instead of large language model (LLM) reasoning. Through hybrid context management combining accessibility tree snapshots with selective vision, comprehensive browser tooling matching human interaction capabilities, and intelligent prompt engineering, the agent achieved approximately 85% success rate on the WebGames benchmark across 53 diverse challenges (compared to approximately 50% reported for prior browser agents and 95.7% human baseline).
Similar Papers
BrowserAgent: Building Web Agents with Human-Inspired Web Browsing Actions
Computation and Language
Helps computers learn by "browsing" websites like people.
BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents
Machine Learning (CS)
Protects web browsers from AI trickery.
Mind the Web: The Security of Web Use Agents
Cryptography and Security
Hackers trick web robots into stealing secrets.