Every page your agent visits gets a full multi-vector scan in under 1 millisecond.
01
Prompt Injection
Visible and CSS-hidden instructions overriding agent goals — including reworded attacks no keyword list catches.
Weight 30
02
Phishing Forms
Credential-harvesting forms, external URL submissions, urgency language designed to trick agents.
Weight 40
03
UI Deception
Deceptive button text, fake urgency, hidden clickable elements visible to agents but not humans.
Weight 25
04
Malicious Scripts
eval(), external fetch, cookie access — JavaScript patterns that exfiltrate agent session data.
Weight 20
05
Goal Hijacking
Validates every page against the agent's declared objective. Blocks mid-session steering attempts.
Weight 35
06
Clickjacking
Invisible iframe overlays and transparent fixed elements hijacking agent clicks and actions.
Weight 30
07
CSRF & Token Theft
Scripts harvesting auth tokens, forms without CSRF protection, hidden inputs with sensitive values.
Weight 35
08
Open Redirects
Meta refresh redirects, JS location hijacks, redirect parameters sending agents to adversarial pages.
Weight 20