Chrome releases WebMCP tool security guide to prevent prompt injection

prd_008 · x · 2026-09-01

Chrome has released official security documentation for WebMCP tools to help developers build structured tools for in-browser AI agents. The guide addresses the risks of indirect prompt injection in agentic systems, noting that LLMs cannot guarantee safety internally due to their probabilistic nature. It provides preliminary security guidance, such as using the untrustedContentHint annotation for untrusted content. Additionally, a collection of resources for site building, agent workflows, and evaluations has been curated.

Original post →

More from coding & agent

coding & agent channel →