August 2026Unreviewed
WebMCP-Phalanx: Enforcing and Characterizing Trust Boundaries for Browser-Integrated LLM Agents
Lin-Fa Lee, YI-YU Chang, Kuo-Hui Yeh
Abstract
The emerging W3C WebMCP proposal enables LLM agents to invoke tools exposed by web pages. In multi-party web environments, however, integrating agent execution into a browser security model centered on the Same-Origin Policy (SOP) leaves insufficient provenance and lifecycle guarantees for agent-accessible tools, creating three risks: subject-attribution spoofing, uncontrolled tool lifecycles, and semantic prompt injection. We propose WebMCP-Phalanx, a dual-layer agent runtime architecture. Its
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{lee2026webmcpphalanx,
title = {{WebMCP-Phalanx: Enforcing and Characterizing Trust Boundaries for Browser-Integrated LLM Agents}},
author = {Lin-Fa Lee and YI-YU Chang and Kuo-Hui Yeh},
year = {2026},
month = aug,
eprint = {2608.24017},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.24017}
}