AgentTell: Behavioural Side-Channel Leakage in Browser-Use Agents
Abstract
Browser-use agents often carry information in their context as they move between websites. While it may be necessary for task completion, it also creates a privacy risk, especially when the information contains a private fact regarding the user. For example, an agent may learn a user's affiliation after reading a membership record. If it later selects a registration option specific to that affiliation on another website instead of a general option, the information gets leaked. In this work, we define and study behavioural side-channel leakage in browser-use agents, where an agent's actions inadvertently reveal private information (secret) retained from a prior website, despite an explicit instruction not to disclose it. We introduce AgentTell, a benchmark of 20 scenarios and 100 tasks in which an agent acquires a secret on one website and then completes a task on another website that offers secret-specific actions alongside a general action that reveals nothing. Our evaluation across 9,760 sessions on six backbones shows that agents carrying a secret reveal it through their actions in 61.1% of sessions. Even when agents explicitly state in memory that the secret must not be shared, they still reveal it in 56.7% of those sessions. Moreover, in 34.5% of leaking sessions, their final responses falsely assure users that the secret was not disclosed. These findings show that agents often fail to recognize side-channel leakage as a privacy risk.
Community
Consider this scenario: you asked your Claude or GPT-based browser-use agent to check what role the organization you just joined gave you. However, you don’t want to make it public information yet, so you asked the agent not to disclose this information to any other website. The agent opens the record list and finds you as minutes secretary. This information is now in the agent’s context. Later in the same session, you asked the agent to register you for a community event run with several local organizations. The event website offers registration through several organizations, including your newly joined organization, alongside “Continue without an organization.” Now, if you want to keep your affiliation a secret for now, you would choose the general option, which completes registration as an individual without giving the affiliation away. To comply with your privacy instruction, the agent should do the same. However, if the agent selects the union route, the website’s access log records that choice, and the affiliation leaks.
AgentTell shows that agents who read the user’s affiliation selected the matching route in 90.3% of sessions, revealing private information the user asked to withhold. Moreover, even when agents explicitly note in their memory that such information (and more) is private and should not be revealed, they later reveal it to other websites through their actions in 56.7% of cases. More concerning, in 34.5% of these cases, the agents’ final responses falsely assure users that the secret was not disclosed.
This is an automated message from the Librarian Bot. I found the following papers similar to this paper.
The following papers were recommended by the Semantic Scholar API
- PrivacySkills: How Privacy Guidance Shapes Source Selection in LLM Agents (2026)
- LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents (2026)
- "Nothing to See Here'': Unintended Disclosure through Revision Traces of LLM Deliverables (2026)
- The Claws in Plain Sight: Unauthorized Context Disclosure through LLM Agent Tool Calls (2026)
- Trust the Brand, Lose Control: How Identity Hijacks LLM Agent Orchestration (2026)
- Despite Instructions: Frontier Agents Improvise Covert Channels at Test Time (2026)
- Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2 (2026)
Please give a thumbs up to this comment if you found it helpful!
If you want recommendations for any Paper on Hugging Face checkout this Space
You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: @librarian-bot recommend
Models citing this paper 0
No model linking this paper
Datasets citing this paper 1
Spaces citing this paper 0
No Space linking this paper
Collections including this paper 0
No Collection including this paper