The important bit to me is that they consider the agent running as an extension of the user. So the user is visiting Amazon, not Perplexity.
From that lens, that feels like users could be held liable for what these hacking agents are doing. Which in some cases probably makes sense, but certainly not all.
In which cases wouldn’t it make sense?