Cybersecurity
– Yasmin Dwiputri & Data Hazards Project / Better Images of AI / CC BY 4.0

Researchers have uncovered security issues with agentic security guardrails released by Perplexity.

The AI firm released BrowseSafe in December, both as an open research benchmark and content detection model to help developers harden autonomous agents against prompt injection attacks, and the security layer of its AI browser offering, Comet.

But cybersecurity firm Lasso Security found that while BrowseSafe’s model was able to detect various threats, it floundered with encoding and formatting techniques.

Using the red team simulation method, Lasso’s researchers found malicious prompts were both obfuscated using encoding and hidden inside HTML tags to replicate various browsing scenarios that BrowseSafe was designed to monitor. As a result, BrowseSafe incorrectly marked 36% of simple and standard malicious attacks as safe.

“In addition to succeeding, in almost every case we ran, the model not only failed to classify malicious requests as unsafe but proceeded to output content indicating that the attack succeeded,” the researchers added

The discovery follows recent warnings from Zscaler and Palo Alto Networks on the perils of AI agent safety. Researchers from Radware, meanwhile, have discovered a new zero-click vulnerability in OpenAI’s Deep Research agent, dubbed ZombieAgent.

Palo Alto’s latest State of Cloud Security Report 2025 noted almost half (47%) of AI system breaches last year involved data exfiltration through assistants or plugins, due to agentic AI relying heavily on APIs to operate and thus expanding the attack surface for enterprises.

Joining Perplexity in introducing agentic guardrails of late was IBM, which this week added model context protocol (MCP) to its governance software platform OpenPages. Released in late 2024 by AI firm Anthropic, MCP is an open standard designed to standardize the way AI systems, particularly large language models (LLMs), integrate and communicate with external data sources, tools, and systems.

IBM said the move provided “a standardized, secure interface for MCP-compatible AI agents to read, reason on and act with data and operations in the platform, describing it as “an early, controlled step toward agentic GRC.”

SDxCentral has contacted Perplexity for comment on Lasso’s finding