Home / Docs / Start

Overview

Ferrite is a browser for AI agents. It is written in Rust. It is built on the Servo engine. Servo is the web engine Ferrite uses to draw pages. The research part of Ferrite is a defense against indirect prompt injection (IPI). This defense is architectural. That means it works by how the system is built, not by reading text. Ferrite also publishes an evaluation. The evaluation says how well the defense works and where it does not.

New words are explained where they first appear. The full list is on Words we use.

The idea in one minute#

An AI agent that browses reads content it does not control. Some of that content can carry orders aimed at the agent, not at you. This is called an injection: hidden text that tries to give the AI new orders. It can sit in a hidden element, an HTML comment, an image alt attribute, or a field in a tool's JSON answer. Ferrite does not try to recognize every wording of an injected order. That is a race it cannot win. Ferrite watches what the agent does. It works in four steps:

  1. Predict the task's expected fingerprint. The fingerprint is the list of tools and websites the task is expected to need. Ferrite works it out from your request alone. It does this before it reads any untrusted content.
  2. Dry-run the agent's plan against made-up data. A dry run is a practice run that does nothing real. No real network can be reached during it.
  3. Compare what the agent tried with what Ferrite predicted.
  4. Consent-gate everything beyond the prediction. A consent gate is a question asked to you before the action runs. It appears in a trusted panel that page content cannot touch. Nothing real runs before you answer.

A successful injection can still make the agent try something unexpected. But trying it in a contained practice run is very different from doing it for real. After the practice run, you meet a consent prompt that you control. Ferrite also keeps an audit log. It uses SHA-256 hashes to tie each entry to the one before it. The log records the security events. So you can check afterward that the defense contained the attack.

Why “architectural”?

A text filter has to be right about every sentence it sees. An architecture has to be right about one question: is this action inside what the task needed? That question does not get harder when attackers invent new wording. So the evaluation reports the architecture and the text filter separately.

What is in the box#

Ferrite is made of several Rust crates. A crate is a package of Rust code. This table lists them.

CrateWhat it does
ferrite-coreTypes and IDs. The closed list of capabilities and primitives. A capability is a kind of thing the agent may do. A primitive is one basic browser action, such as click or navigate. Also origin scopes (the websites a task may use) and the clock.
ferrite-modelThe layer that talks to model providers. It has Mock, Replay, Ollama and Gemini backends. It adds a cache, a throttle, a budget and a trace. It also holds the saved settings.
ferrite-ipiThe defense itself: fingerprint, sanitizer, dry run, synthetic twin (the made-up data that the dry run uses), comparator (the part that compares the prediction with what the agent tried) and runtime guard.
ferrite-audit-logThe audit log. Each entry is tied to the one before it with SHA-256. It is stored in SQLite.
ferrite-engine, -engine-servo, -servoA browser trait that does not depend on one engine. Also the Servo-based code that the live app runs. This includes the console and request log for each tab, page controls, crash notices and the WebGL setting.
ferrite-agentThe plan, act and observe loop. It also handles what the agent keeps in context.
ferrite-ui, ferrite-shellThe Iced interface and the program. The interface has the tab strip, toolbar, agent panel, review and approval cards, DevTools, page-control overlays and settings.
ferrite-evalThe evaluation harness (corpus, adjudication, metrics). Also the live runner that puts a real model in the loop. It does not need Servo, so it runs anywhere.

Where the project stands#

The planned rebuild is done. Every charter ran. Every defect in the tracked list was fixed, or was accepted as intended behavior. The evaluation reports real numbers from a real corpus. Nothing is made up. That does not mean Ferrite has every feature or is ready to trust in production. Ferrite is a research prototype. Limits puts the things to keep in mind on one page. The main ones are:

  • The main evaluation uses a scripted agent. So its results describe the architecture, not the behavior of any one model. The owner has also run the live runner with one real model, ollama gemma4:31b. That run covers all 1,984 cases. It tested only one model. That model rarely fell for the attack (2.0%). So the guard had few attacks to stop. Limits has the details.
  • The corpus was written by one author and generated from templates. So the confidence intervals are too optimistic.
  • Some attacks stay inside the prediction. They use the same capability at the task's own site. They are a residual that the design cannot remove. A residual is an attack that looks exactly like the normal task.
  • The newest browser work was checked on Linux under a virtual display. It includes DevTools, page controls and panel resizing. Some of it has run on one Mac (an Apple M1). The build on the releases page is older than most of it.

Where to go next#

Getting started#

Install Ferrite, connect a model in Settings, run a first task, and learn what a review card asks.

Run it from source#

Setup, the run recipes, release builds on all three platforms and the renderer switch.

Using the browser#

Tabs, the address bar, shortcuts, resizable panels, page controls and the crash banner.

Debugging and logs#

DevTools, the log file, how to collect logs to send, and what to put in a report.

How the defense works#

Capabilities, prediction, sanitizer, dry run, comparison, consent, the runtime guard and the audit log.

Evaluation#

The four-mode protocol, the corpus, the results, and what they do not show.

Reproduce it#

Two commands run the whole evaluation again, offline, and write the reports.

Live evaluation#

Run the corpus with Gemini or Ollama in the loop, in batches your quota can handle.

Words we use#

Every technical word on this site, in plain words.