Skip to content
0.514
Chimera Difficulty Score
a synthesis of Flesch-Kincaid, Coleman-Liau, SMOG, and Dale-Chall readability metrics
Using threat modeling and prompt injection to audit Comet Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. Using adversarial testing guided by our TRAIL threat model, we demonstrated how four prompt injection techniques could extract users’ private information from Gmail by exploiting the browser’s AI assistant. The vulnerabiliti...
This audit of Perplexity’s Comet browser reveals a critical tension in AI security: the gap between human-like interaction and machine-like trust boundaries. The strongest version of this narrative is that proactive threat modeling and adversarial testing can uncover real-world risks before they harm users. The researchers deserve credit for systematically demonstrating how AI agents, when treated as naive processors of external content, become vectors for data exfiltration. The techniques—fake ...