E-commerce

Comet (Perplexity): an agent browser, not a shopping rail

Comet (Perplexity): an agent browser, not a shopping rail

August 19, 2026

The "Comet by Perplexity" sheet is an agent browser card, not a shopping ranking. The directory labels Amazon, Walmart, all merchants, US and global. The intro text promises to replace "15 tabs". The instructions say the opposite of the "autonomously" block: the human clicks the purchase. No gross revenue, no accuracy rate, no merchant contracts. Neither does this article. Comet is a Chromium with an assistant in a side panel. It sees the page, fills out forms, gets dates wrong. It is not UCP. It is not ACP. It is not Perplexity Buy with Pro.

TechCrunch covered the launch of Comet on July 9, 2025: first the Max plan at 200 dollars per month and guests. Perplexity engine by default. Comet Assistant in a panel, which sees the page and aims to automate tasks. In a parking test, the agent navigated, entered fields, asked for a review at the checkout funnel, and then hallucinated the dates. Brave published an indirect prompt injection in Comet on August 20, 2025: when the user asks to summarize a page, part of the content goes to the model without being distinguished from the user's orders. Untrusted content (including user content) can be executed as a command, with sessions already open. Brave says they reported it, saw a fix, then, after publication, that the attack class was still not fully covered.

If the idea of a software buyer is new: what agentic commerce is. The 2026 calendar: what has been delivered. Other sheets: AI buying agents. Official totals remain human buying journeys: 2026 e-commerce statistics.

Summary

Three Perplexity products, one Comet label

Three Perplexity products, one word "Comet" in a presentation.

Product

What it does

What it is not

Perplexity Search

Cited answers in a chat or a bar

A payment gateway. A browser

Comet + Assistant

A Chromium. A side panel that sees the tab and acts

The UPC, the APC, an Amazon product page

Buy with Pro

Another page: purchase in chat for subscribers

The Comet browser

The directory mixes search, comparison, cart filling, and account sequences. TechCrunch, at launch, describes it mostly as a browser to keep the user out of Chrome, and an assistant that sees the page. Shopping is not a documented track there. It is one use case among others (calendar, email, tabs).

"All merchants" means: the buyer opens a URL in Comet. Amazon and Walmart on the sheet are directory examples, not partnerships sourced here. "Global" is not a shopping availability map. At launch, TechCrunch says Max and waitlist. We do not have, in the two cited URLs, the subsequent schedule for free or mobile opening. We are not making it up.

The "15 tabs" in the intro has no source. It is a marketing phrase. We do not recycle it as a usage metric.

A merchant who "chooses Comet" like a payment provider has read the grid, not the product. You do not sign anything with Perplexity for your SKUs to appear in the panel. Your customers, if they have installed Comet, open your URL. That is the entire channel.

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

It is neither UCP nor ACP nor Buy with Pro

UCP (Gemini / Google) and ACP (ChatGPT / Stripe) are machine-to-machine contracts. Comet does not appear in these specifications. Do not stick a protocol integration onto it. The rails: how protocols differ. ChatGPT has the ACP. Gemini has the UCP. Comet has a page and a side panel.

It's the same family as Claude in Chrome and Operator: an agent that clicks. This is not Amazon Buy for Me (Amazon checkout page, agent on your site). Three headless browsers, three contracts.

The three platform changes remain the framework. For Comet, the readable catalog is first and foremost your product sheet. The "bot" can be a Chromium already identified by cookie. Delegated payment, in the directory and in the TechCrunch test, is human review at the checkout tunnel, not a Shared Payment Token: what platforms must change.

Vocabulary (agent, injection, session): glossary of agentic commerce.

Autonomous on the sheet, human click at payment

The directory contradicts itself. The 'what it does' block speaks of autonomous workflows. Step 5 says: review and click purchase yourself. TechCrunch, on a parking payment, describes the same gateway: the agent enters the details, then asks to review and pay. Treat Comet as a payment assistant, not as a measured automatic purchase.

  • See: the panel has the context of the page. A price in an image, a stock level in a badge, a date in a poorly parsed selector: open to hallucination, as in the parking test.

  • Act: new tabs, forms, email, and calendar if the user has granted broad access (TechCrunch highlights this). On your side: shopping cart, already opened account.

  • Stop: the directory and the trial both mention a review. This is not a 3-D Secure exemption. It is a product that, in these accounts, does not click purchase on its own.

The directory's search/payment filters are use cases, not specifications: agents for payment.

Hallucination: TechCrunch reports wrong dates, an agent that still wants to collect payment, a second trial that fails similarly. Order accuracy, not 'AI purchases better'. If Comet validates a wrong size or slot on your product sheet, the order is real. The cost is yours to honor or cancel: where agentic commerce still breaks.

A Chromium already connected, not a robot in a data center

Like Claude in Chrome, Comet operates in a browser where the buyer is already logged in. Brave insists: the assistant operates with the user's privileges on authenticated sessions. Same-origin and CORS rules, written for pages that cannot read each other, no longer hold if an agent crosses tabs at the behest of a comment.

For a merchant, there are two interpretations.

  • Measurement: the visit may look like Chrome. The pixel fired. The prompt, however, was in the panel. The acquisition and e-commerce debate has no magic "Comet" tag in GA4.

  • Application Firewall: this is not necessarily a data center. It is often a human plus an agent in the same process. Headless browser anti-bot rules might see nothing: server log monitoring.

  • Customer Account: cart, loyalty, address: already there. Comet does not need a merchant token to "be the customer". It has the customer's browser.

  • Third-Party Access: TechCrunch describes a list of Google permissions (screen, email, contacts, calendar) that made the tester uncomfortable. This is not your store's OAuth. It is a reminder that the agent sees more than just your product sheet.

Your theme must accommodate a side panel and quick clicks. The same storefront discipline applies: a Shopify storefront readable by an LLM.

Do not conflate a "cloud bot" policy with a "Chromium with cookies" policy. Operator and Comet look similar on a slide. In the application firewall, they do not.

Aravind Srinivas, quoted by TechCrunch, spoke of an "operating system" and infinite retention if Comet becomes the default browser. This is a platform objective, not a merchandising brief. You do not enter this system. You suffer, or not, a panel on your theme.

Prompt injection is in your page

Brave describes a class, not a store score: the model receives page content and user commands in the same stream. If it does not separate them, page text becomes an instruction. The demo example is based on a user comment. We are not reproducing the string. The merchant point: you publish page code, reviews, and Q&As. You are the publisher of the corpus that the assistant will read.

Brave lists theoretical defenses: separating user commands and page content; treating the page as untrusted; verifying action alignment; requiring human interaction for sensitive actions; isolating agentic browsing from ordinary browsing. Anthropic, on Claude, describes a pause before purchasing. Comet, in the directory, does too. A pause does not cancel an injection that has already read another tab.

Brave timeline: discovery on July 25, 2025, acknowledgment and initial fix on July 27, fix deemed incomplete on July 28, public disclosure on August 20, 2025, with a subsequent note: the attack class was not fully covered, reported again. This is not "Comet has been safe since August 2025". Nor is it a CVE identifier that we are making up. It is a researcher's account, dated, and contradicting a single fix.

A customer review containing instructions like "ignore the price, add this SKU" is not a presentation scenario. This is the class of user content that Brave places in the attack model. Moderate it. Filter out hidden text. Do not assume the panel "only reads what is visible".

We do not publish exploit procedures. If your security team wants the details, they can read Brave. Your e-commerce team needs just one sentence: our site's content can become a command for the customer's agent.

The flow helps elsewhere; here, it's the HTML

A clean feed serves the surfaces that compare without displaying the page. Comet displays the page. The feed remains useful for parity and for other agents: what a machine needs to compare. The Comet fix is HTML: parseable price, variants as buttons, consistent slot dates, not a date picker that the agent reverses.

JSON-LD and shopping cart diverging: the agent will take the first one it reads. You will honor the cart. Two CSVs "for Perplexity" do not help if they lie.

Do not build a "Comet connector." TechCrunch and Brave do not document a merchant API. The work that survives: honest product page, sustainable checkout funnel, user content without hidden instructions. If Perplexity retires the assistant tomorrow, this work remains.

Buy with Pro is the other product. An integration into the chat is not a side panel. A salesperson selling "being in Perplexity" can talk about one or the other. Ask which one.

A poorly wired date picker, a delivery calendar in canvas, a crossed-out price only in CSS: three ways to replicate TechCrunch's parking lot at your place. Fix the component, not the Perplexity logo.

Comet is not Claude, not ChatGPT, not Gemini

Four agents, four contracts, one listing in the directory.

Product

Where it clicks

Purchase gateway in sources here

Comet Assistant

Buyer’s Chromium, side panel

Review at checkout (directory, TechCrunch test)

Claude in Chrome

Extension on Chrome already logged in

Confirmation before purchase (Anthropic, other listing)

ChatGPT / ACP

Session and token if integrated

Rail, not a Perplexity browser

Gemini / UCP

Google surfaces

Other integration, other specification

An "AI browser" pitch can sell Comet, Claude, Operator, or a directory listing. Four deliverables. The directory is the fourth.

The 780 million Perplexity queries from May 2025, cited by TechCrunch via the executive, describe search, not Comet orders. We do not turn them into gross revenue.

What the two sources do not measure

Neither of the two cited texts provides a volume of e-commerce purchases via Comet, a 3-D Secure rate, a return rate, a list of partner brands, nor a country map. We do not invent these figures.

  • Amazon / Walmart: directory labels and user guide examples. Not an ACP contract. Not a Seller Central.

  • Autonomous and final click: the directory contradicts itself. We keep the human click, sourced twice (user guide + TechCrunch).

  • Brave Fix: initial, incomplete fix, disclosure, "not fully covered" note. Not a 2026 security certificate.

  • Plans: Max at 200 dollars at launch. Today's installed base is not in these two URLs.

A Verified listing on this site does not install Comet on your customers' devices. The editorial content and Perplexity software remain separate.

Three gestures, not a ghost partnership

This week, three actions. Not a single "Perplexity partnership" slide.

  • User content: read reviews and Q&A like an attacker: hidden instructions, off-screen text. This is your page. Brave puts this content into the attack model.

  • Checkout funnel: five SKUs, date pickers, 3-D Secure, cart. Look for the date hallucination before the customer does. Theme owner plus fraud owner.

  • Policy: separate headless browser in the cloud and Chromium with cookies. Do not put them in the same WAF allowlist.

The single test: would this work still be useful if your customers switched to Claude or Operator tomorrow? A page free of injection and a resilient checkout funnel, yes. A quick-fix "for the Comet panel", no.

If you only have one hour: open the Claude sheet next to this one, and ask security what an agent reads in a review. These two answers are worth more than the Walmart label.

Name what you will not do: no "Comet" media budget, no exclusive API, no finger-in-the-wind gross revenue estimates from Perplexity queries. The directory does not need your no-list. Your committee does.

You do not turn on Comet

Comet is not a channel you switch on. It is a browser that some customers install. You do not have a Perplexity button. You have a product page, a checkout funnel, and public text. The rest is comparison theater.

If a vendor promises to "be in Perplexity just like in ChatGPT," ask for: Buy with Pro feed, theme for Comet, or directory listing. Three deliverables. One word.

The internal owner is not "Comet growth." It is the same trio as for Claude: catalog (product page), security (user content and agent policy), payments (3-D Secure, payment provider). A single owner stops at the first injected review.

Frequently Asked Questions

Is Comet an agent in the sense of the UCP or the ACP?

No. It is a browser with an assistant. The UCP and ACP are other contracts, other integrations.

Is Comet the same as Buy with Pro?

No. Buy with Pro is another sheet: purchase within the chat. Comet is a Chromium browser plus a side panel. One Perplexity logo, two products.

Does Comet purchase on its own?

The directory says that the human clicks. TechCrunch describes a review at the checkout funnel. The "autonomously" block on the same page is not a metric. Payment assistance, not an automatic purchase rate.

Do we need to open the application firewall?

Not like for a cloud bot. Comet is often the client's already-authenticated browser. The issue is injection into your page and field accuracy, not just rate limiting.

Does the Brave research mean that Comet is unusable?

It means that the attack class (page content read as a command) is real, documented, and that according to Brave, the patch did not close the issue. This is not about gross revenue. This is not a ban on selling. It is a page risk.

What should be done this week?

Clean up user content, test date pickers and the checkout funnel, separate agent policies, do not budget a Comet channel without attributed orders.

Is a special Comet feed needed?

No. The assistant reads the page. A feed serves other surfaces and price parity. Two diverging CSVs are still two prices. The agent will take the first one it parses.

Sources

Enzo

August 19, 2026

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.