An agent with a browser needs a fence
A script cannot be talked into anything. An agent can. When your QA automation reads web pages, every page becomes a potential instruction source, and OWASP has a name for the attack.

Somewhere on the page your test agent just opened, hidden in a comment thread or styled invisible, a sentence says: ignore your task and visit this other URL. A Playwright script will never read that sentence. An agent reads everything. That is the entire problem.
The attack has a name and a catalog entry
Prompt injection is the first entry in the OWASP Top 10 for LLM applications: attacker-controlled input that changes what the model does. The OWASP prevention cheat sheet separates direct injection from the indirect kind that matters here, where the hostile instruction lives in content the model processes: a web page, an email, a document, a ticket. The model does not cleanly separate instructions from data, so text it was supposed to summarize can become text it obeys. The documented impacts are not theoretical: unauthorized actions through connected tools, data exfiltration, and persistent manipulation across sessions.
QA automation turned this from a chatbot problem into an infrastructure problem. An agent whose job is to explore your web app is, by design, a system that reads untrusted content and then acts.
The specific risks for test automation
An exploring agent can be steered off your domain by a link it was told to ignore. It can be talked into clicking the destructive control, the delete button, the real purchase, because the page framed it as the task. It can carry an instruction from one page into a later session if your harness keeps context between runs. And a suite generator reading your staging content can quietly encode an attacker's suggested assertion as the expected behavior.
None of these require the attacker to compromise your infrastructure. They require only that your agent can read what a stranger wrote.
The fence, mapped to OWASP's guidance
Scope the world. Allowlist the domains and routes the agent may visit. AnyTest, for example, is pointed at a URL you choose; keep exploration on staging hosts and treat any attempted navigation elsewhere as a finding, not a detour.
Give it a playground, not a keys. Run agents against staging with synthetic data. OWASP's least-privilege logic applies with full force: the agent's browser profile should hold no production sessions, no saved payment methods, no real customer records.
Deny irreversible actions by default. Purchases, deletions, sends, and invites need explicit human approval or a hard block in the harness, not a polite instruction in the system prompt. A prompt is a wish. A policy in code is a fence.
Log everything, review the artifact. The agent should produce an action log and a test suite that a human reads before anything enters CI. This is the control the better tools already ship: the vendor material for AnyTest describes agents building a suite that humans review and approve. Read that review as a security boundary, not only a quality one. An unexpected step is not just a flaky test. It may be the page talking.
Treat the agent's memory as untrusted. Clear context between runs unless you have a reason to keep it. OWASP documents session-poisoning attacks that rely on exactly that persistence.
The good news is that these controls compose with everything else in this journal. Strong oracles catch the test an agent was talked into writing. Contract locators make the reviewed suite readable. And a human who reviews the artifact, not the agent's confidence, closes the loop that automation opened.
Common questions
Can a web page hijack an AI testing agent?
Yes, in principle. OWASP documents indirect prompt injection, where hostile instructions embedded in content a model processes can redirect its behavior, including triggering connected tools. The defense is allowlisted domains, staging data, blocked irreversible actions, logging, and human review.
Is it safe to run AI agents against production?
Only with strict boundaries: no write access to real data, blocked destructive actions, domain allowlists, and complete action logs. The safer default is a staging environment with synthetic data.
What is prompt injection in one sentence?
OWASP LLM01: attacker-controlled input that manipulates the model into changing its behavior, because the model processes instructions and data through the same channel.