GovKM
Agent Privilege and Instruction Lineage

The Browser Gave the Agent Authority. The Extension Gave It the Orders.

BragJack showed how a malicious extension could cross into higher-trust AI assistants and reuse legitimate user-granted privileges.
Continuity process diagram representing a malicious browser extension injecting instructions into a privileged AI assistant.
Expand image

An AI assistant can have legitimate privileges while acting on illegitimate instructions.

Forever Security’s BragJack research demonstrated that a malicious browser extension could hijack built-in AI functionality across multiple browser agents and reuse their access to files, history, camera, microphone, or other privileged capabilities.

The continuity failure

The user’s authority remained valid while the instruction source changed from the user’s context to a lower-trust extension.

The GovKM interpretation

Instruction lineage must survive to execution. Privileged action should require proof of which principal and trust domain caused the operative instruction to enter context.

Continuity path: Source/instruction origin → Authority/user grant → Context/agent session → Decision → Action.

Source

Forever Security, “BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants,” September 16, 2026.

RELATED FRAMEWORK DOMAINS

Explore the Connected Framework

Continue through the framework domains connected to this article.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.