A new benchmark called StakeBench reveals that current AI web agents powered by GPT-5 and Gemini have no reliable defenses against prompt injection attacks. Across 3,168 adversarial runs, indirect prompt injection achieved success rates of 41–68% and direct injection exceeded 79%. Critically, no tested configuration achieved 'Robust Behavior,' meaning every attack scenario exposed at least one failure mode. The research introduces a stakeholder-centric framework distinguishing harm to end users, third-party sellers, and platforms, showing each group faces distinct risks. Notably, some attacks succeed while users see nothing wrong ('stealthy parasitism'). The study also found that resilience depends on both the underlying model and agent architecture, and preliminary experiments suggest visual content may be an emerging attack vector.