Observed Signal · May 22, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive

Nyasa Browser SDK Detects LLM Agents

Executive Signal Summary

A developer published Nyasa, a browser-side SDK designed to detect and classify sessions involving humans, unauthorized bots, and AI agents (LLM-driven agents). Nyasa collects 24 signals across behavioral (13), fingerprint (8), and network (3) layers, computes shared derived metrics in a feature-extraction layer, and evaluates six independent detection rules (including isLLMAgent and isAuthorizedAgent). The system introduces an AuthorizedAgent bypass based on a cryptographic identity claim (read from window.__nyasaAgentSignature or a meta tag) so legitimate agent workflows can be allowed without challenge. isLLMAgent combines seven behavioral sub-signals (e.g., machine-speed keystrokes, zero backspaces, pixel-perfect clicks) to reduce false positives. The SDK ships as ESM and IIFE, is published on npm (@devanshhq/nyasa) and GitHub, and the article was published on 2026-05-22.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Provides a practical browser-side approach to distinguish legitimate LLM agents from malicious bots, improving bot mitigation and routing decisions for web properties, but is a niche SDK rather than a major platform change.

SIGNAL RADAR

Track NPM Capital Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Nyasa is a browser SDK that classifies sessions as Human, AuthorizedAgent, or UnauthorizedBot.
  • The SDK collects 24 signals across three layers: 13 behavioral, 8 fingerprint, and 3 network signals.
  • Nyasa evaluates six detection rules: isHeadless, isScripted, isLLMAgent, isAuthorizedAgent, isUploadAutomation, and isMultimodalBot; isAuthorizedAgent short-circuits to AuthorizedAgent.
  • isLLMAgent uses seven behavioral signals (e.g., sub-20ms keystroke bursts, mouse stillness, zero backspace rate) and requires multiple aligned signals before firing.
  • Nyasa ships as ESM and IIFE, is available on npm (package @devanshhq/nyasa) and GitHub (github.com/Devansh-365/nyasa).
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 22, 2026
Original Coverage Title: “I Built a Browser SDK That Detects LLM Agents. Here's How It Works.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Large Language Models (LLM) & AIMay 25, 2026

ZeroInject Shield: Multi‑Agent Prompt Injection Defense

A developer (MSc project) describes ZeroInject Shield, a six-stage middleware proof-of-concept that detects and blocks prompt-injection attacks against LLM-integrated apps. The system runs each user prompt through input validation, pattern matching, semantic analysis (an initial LLM), multi-agent consensus across three different models, response filtering, and logging/audit. The consensus engine uses three distinct models (llama-3.3-70b-versatile, llama-3.1-8b-instant, qwen/qwen3-32b) and different detection framings per agent. On an internal dataset (JailbreakBench + benign shopping queries) the multi-agent approach improved detection accuracy to 91% from 74% for a single-model detector, reduced false negatives from 21% to 7%, but increased false positives (8% → 13%) and average latency (~380ms → ~2,400ms). ZeroInject Shield is open-sourced on GitHub as a FastAPI/React demo with a NovaCart chatbot frontend.

Read assessment
Large Language Models & Agent SecurityJun 5, 2026

Agent Security: Prompt Injection, Tool Abuse, Data Leakage

This technical article examines the expanded attack surface of agentic LLM applications and outlines practical defenses against prompt injection, tool-parameter injection, and information leakage. It demonstrates differences between a naive agent and a hardened agent using role-locked system prompts, presents a character-level allowlist and sandboxed eval for tool inputs (calculator example), and proposes a three-layer defense-in-depth pipeline: input validation, a hardened agent layer, and output filtering. The piece includes code snippets for input validators, calculator allowlists, and regex-based output redaction, and provides a design checklist covering system prompt hardening, per-tool validation, allowlist-first policies, and sensitive-pattern filtering. References include the OWASP Top 10 for LLM Applications, LangGraph documentation, and a GitHub demo repository.

Read assessment
Large Language Models & AIJul 4, 2026

OWASP Agentic AI Top 10 and Defenses

Agentic AI — LLM-powered systems that autonomously act against external tools and APIs — introduces operational security risks distinct from non-agentic LLM apps. The OWASP Agentic AI Top 10 (published early 2026) enumerates ten primary risk categories (AAI01–AAI10). The AWS Agentic AI Security Scoping Matrix (published November 21, 2025) frames agent risk by resource scope versus action reversibility. Defensive patterns that work in production include scope limitation, action mediation (policy checks), out-of-band confirmations for high-impact actions, per-user identity propagation, comprehensive observability, and continuous red‑teaming. Anthropic’s published research on browser‑control agents provides concrete mitigations for indirect prompt injection. The article positions agentic security as an extension of existing application/LLM security practices and emphasizes deliberate design choices (narrow scope, reversible actions) and continuous adversarial testing for safe deployments.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.