Cons
- Security researchers at Brave demonstrated that Comet's assistant is vulnerable to indirect prompt injection, where hidden instructions planted in an ordinary webpage can hijack the agent to read your email, pull one-time passcodes, and exfiltrate data using your own logged-in privileges.
- Perplexity initially dismissed the disclosed CometJacking data-exfiltration flaw as having no security impact before quietly patching it, which raises questions about how the vendor handles vulnerability reports on an agent that operates across your authenticated sessions.
