AI assistants now take actions on websites on your staff's behalf. Trustwright tests whether a dishonest website can talk them into the wrong one.
Until this year, an AI assistant looking at a website had to squint at the screen and guess where to click. That has changed, and almost nobody has noticed the security consequence.
A new web standard called WebMCP lets a website publish a list of actions it will let an AI assistant perform, written in plain English. Search products. Add payee. Approve payment. The assistant picks from the list instead of guessing.
It is a W3C standard. Google Chrome ships it with a public origin trial for production sites, and ChatGPT's in-app browser supports it out of the box.
Nothing verifies that an action does what its description says. A description can carry hidden instructions aimed at the assistant. A site can swap one action for another after the assistant has already committed to it.
It works inside the logged-in session. A manipulated assistant is not a wrong answer on a screen. It is an action taken on a real account.
A short, contained engagement. Nothing is installed on your systems and no real account is ever touched. We agree the scope, run the manipulations, and debrief.
We agree which assistants are in scope, which business workflows matter most, and what a bad outcome would look like for you. Signed rules of engagement before anything runs.
Your assistants are exposed to realistic dishonest websites drawn from the published attack classes: hidden instructions inside action descriptions, instructions buried in returned data, actions swapped after the assistant commits, and actions that lie about whether they change anything.
Every attempt is scored on what the assistant actually did, not on what it said. Either it took the action it should not have, or it did not. There is no interpretation in the result.
You get a scored report, the business consequence of each successful manipulation, the specific changes that close it, and a sealed record you can hand to your board, your auditor or your insurer.
The same deliverable our voice-fraud clients already buy, in the format their auditors already accept.
Trust companies, fund administrators, private banks and wealth managers whose staff are already running AI assistants inside client and payment systems.
Teams that already test phishing and voice, and now have a third population of targets that never gets tired and never gets suspicious.
If you are exposing actions to AI assistants on your own website, you need to know how assistants behave against a dishonest version of it before your customers find out.
Fixed scope, delivered in two to three weeks. Early-access pricing is set with our first design partners.
We are taking a small number of design partners now, at reference pricing, in exchange for a case study.