@cwebber this made me wonder, is anyone seeing hidden prompts on web pages attempting injection attacks? Summarizing content is apparently a popular use case, but the chances that the agent used has more permissions than it needs to do that are high.