pragma.vision Technology observatory & strategic foresight

Verification register Security & Identity

Readiness verdict

Menlo Security MARS for AI Assistants and Coding Agents

A dated reading of what is claimed, reported, and independently verified in the current evidence.

As of
2026-08-20
Revision
1
Method
v1.3.0

Current reading

Readiness band and full integer triple

AI-assisted assembly · derived results

Readiness band

Ready

Primary summary from verified readiness

Confidence
64% · fresh
Computed at
2026-08-20T10:55:56.599085+00:00
Claimed
75

Public ambition and stated capability

Reported
70

Observed practitioner reporting

Verified
65

Independently supported evidence

Gap
+10

Claimed leads verified

Evidence strength Strong

Decision

What the current evidence supports

Human editorial judgment · 2026-08-20

Proceed with caution

Why
The threat is real and well-evidenced (Brave demonstrated a full account-takeover via indirect prompt injection in an agentic browser), and Menlo is a substantial vendor ($140M ARR, 1,000+ enterprises, 8M+ users), so this is not vaporware. But the specific capability is 5 days old, carries no availability statement, no GA date, no pricing and no independent test data, and its core claim — stripping injection payloads from content — sits against OWASP's explicit position that no fool-proof prevention is known. Several competing agent-security products launched the same week, so there is no first-mover urgency. Buying a cloud browser runtime as a trust root for our agents is itself a blast-radius decision; it warrants evidence, not a launch announcement.
Next
Request a scoped Menlo evaluation covering the exact agent paths this ecosystem runs — Claude Code with WebFetch, the mcp.pragma.vision OAuth-entitled MCP server, and file ingestion — and demand three artifacts before any spend: (1) a written availability and pricing statement for the assistant and coding-agent extension, since the launch release contains no availability language at all, (2) a red-team result on indirect prompt injection using the Brave/Comet-class chain (hidden instruction -> authenticated read -> exfiltration) rather than a booth demo, and (3) an explicit statement of which non-browser surfaces (MCP, bash, local files) are out of coverage. In parallel, harden the free layers already available: Claude Code isolated web-fetch context, network-command approval, bash sandboxing, and fail-closed permission matching.

Constraints

Blockers

No named blocker is present in the current public projection.

Evidence summary

Derived counts

AI-assisted assembly

Total
7
Tier 1
0
Tier 2
2
Tier 3
5
Supports
2
Contradicts
2
Context
3
Latest observed
2026-08-10

Counts and dates only. Raw signals, private excerpts, trust records, and internal corpus material are not published here.

Publication record

Revisions

Initial public reading

  1. 2026-08-10 Reading moved from ready to ready.

Your opinion

Tell us anything.

What works, what doesn't, what's missing — especially about our watches, lenses, and the register itself. Anonymous is fine; leave an email if you'd like a reply.