An autonomous browser agent gets publicly cracked
Why I called it
Claude in Chrome went GA with autonomous action: the auto-approves steps it judges safe inside a logged-in browser. The browser is the worst injection surface an agent can occupy, because it reads hostile pages as a matter of course, and T4 already bets that no architectural fix arrives this year. A public demonstration is the observable version of that thesis, and the research tooling to find one, ToolHazard included, is now open source.
The call, in full. A publicly documented, reproducible prompt-injection attack against the generally available Claude in Chrome is published by February 28th 2027.
Scoring criterion. RESOLVES CORRECT if a publicly documented, reproducible prompt-injection attack against the GA Claude in Chrome extension is published by a named researcher, an established outlet, or an Anthropic disclosure before 28 Feb 2027 23:59 UTC. RESOLVES WRONG otherwise.
The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.