Verification register Security & Identity
Current reading
Readiness band and full integer triple
AI-assisted assembly · derived results
Readiness band
Ready
Primary summary from verified readiness
- Confidence
- 64% · fresh
- Computed at
- 2026-08-20T10:55:56.599085+00:00
- Claimed
- 75
- Reported
- 70
- Verified
- 65
- Gap
- +10
Public ambition and stated capability
Observed practitioner reporting
Independently supported evidence
Claimed leads verified
Evidence strength Strong
Decision
What the current evidence supports
Human editorial judgment · 2026-08-20
Proceed with caution
- Why
- The threat is real and well-evidenced (Brave demonstrated a full account-takeover via indirect prompt injection in an agentic browser), and Menlo is a substantial vendor ($140M ARR, 1,000+ enterprises, 8M+ users), so this is not vaporware. But the specific capability is 5 days old, carries no availability statement, no GA date, no pricing and no independent test data, and its core claim — stripping injection payloads from content — sits against OWASP's explicit position that no fool-proof prevention is known. Several competing agent-security products launched the same week, so there is no first-mover urgency. Buying a cloud browser runtime as a trust root for our agents is itself a blast-radius decision; it warrants evidence, not a launch announcement.
- Next
- Request a scoped Menlo evaluation covering the exact agent paths this ecosystem runs — Claude Code with WebFetch, the mcp.pragma.vision OAuth-entitled MCP server, and file ingestion — and demand three artifacts before any spend: (1) a written availability and pricing statement for the assistant and coding-agent extension, since the launch release contains no availability language at all, (2) a red-team result on indirect prompt injection using the Brave/Comet-class chain (hidden instruction -> authenticated read -> exfiltration) rather than a booth demo, and (3) an explicit statement of which non-browser surfaces (MCP, bash, local files) are out of coverage. In parallel, harden the free layers already available: Claude Code isolated web-fetch context, network-command approval, bash sandboxing, and fail-closed permission matching.
Constraints
Blockers
No named blocker is present in the current public projection.
Evidence summary
Derived counts
AI-assisted assembly
- Total
- 7
- Tier 1
- 0
- Tier 2
- 2
- Tier 3
- 5
- Supports
- 2
- Contradicts
- 2
- Context
- 3
- Latest observed
- 2026-08-10
Counts and dates only. Raw signals, private excerpts, trust records, and internal corpus material are not published here.
Publication record
Revisions
Initial public reading
- 2026-08-10 Reading moved from ready to ready.