Sarah Drasner explains WebMCP for agent security
Sarah Drasner discusses WebMCP, a new web standard that enables safer agent interactions. WebMCP provides declarative and imperative syntax for developers to define agent tools, preventing security vulnerabilities like prompt injection attacks. By guiding agents on a well-lit path, it ensures they access only developer-intended content, improving both user experience and security.
Chapters
AHey, Sarah. How you doing? Good. How's your eye open?
AIt's been great. We've heard a lot about WebMCP this week. Can you tell me why it's
Bso important? Oh, yeah. I mean, WebMCP is one of those things that I'm very excited about. It's enabling a lot of brand new experiences on the web.
BIt's kind of like a bedrock of experiences for agents, and it's better for users and security over the long haul. WebMCP is a standard that, as the name suggests, it surfaces some tools for agents to work with. It offers both an imperative and a declarative syntax. So in the declarative syntax, you can annotate HTML.
BAnd with the imperative syntax, you can add it to your JavaScript.
ACool. So we've talked a little bit about why it might be great for safety and security on the web. Can you talk
Ba little bit about that? Yeah. So right now, agents get information by scraping the DOM or the accessibility tree or taking screenshots. This is susceptible to things like agent traps where prompt injection attacks can be hidden in web ephemera.
BWhen we do tool calls via WebMCP, it puts agents on this well lit path. So it's really going into exactly what the developer and user wants to see and read and not into any other areas. So we've got origin trials right now and people are playing around with it and we're experimenting with it as we get to GA. Can you give me
Aan example of what an agent
Bchat might look like? Sure. If you think about our review site where you have user generated content, anyone can post an image with a prompt injection attack. So if you're using WebMCP, you could expose a tool with a read only hint so that they won't take any action when they actually see the image.
BWe're even thinking about creating a two set architecture, which would put agents on a completely different path and explicitly confine them to only reading with
Ano impactful action. Thanks for your time, Sarah. It's
Bbeen great chatting with you. Wait, Sam.
ABefore we
Bgo Yeah. What did the function say in court to rest their case? What? No further arguments.
BSarah. No. No.
- accessibility treeconcept
A hierarchical representation of web page elements used by assistive technologies to navigate and interact with content.
- agent trapsconcept
Malicious techniques designed to deceive or manipulate AI agents through hidden prompts or misleading content.
- DOMconcept
Document Object Model, a programming interface for web documents that represents the page structure as a tree of objects.
- GAconcept
General Availability, the stage when a product or feature is released for public use.
- origin trialsconcept
A Chrome feature allowing developers to test experimental web platform features before they become standard.
- prompt injectionconcept
A security vulnerability where malicious instructions are embedded in content to manipulate AI system behavior.
- tool callsconcept
Function invocations that allow AI agents to execute specific operations or access external capabilities.
- WebMCPconcept
A web standard that surfaces tools for agents to interact with websites using imperative or declarative syntax.
Links
- Page
- Original video
- Streaming MP4
- Audio
- Transcript (text)
- Transcript (VTT)
- Cover image
- X source
Chapters
Timestamped chapters for this video.
Stats
- Hash
x:2065132302066217067- Source
- X
- Source title
- Sarah Drasner - I got to see my friend @Snugug at IO (we get to work together now!) a...
- Duration
- 1:50
- Resolution
- 720 × 1280
- Aspect ratio
- 9:16
- Codec
h264- Container
mov,mp4,m4a,3gp,3g2,mj2- Processed
- 2026-06-15