Hidden DOM hijacks your model.
Pages can plant instructions in DOM nodes the user never sees — display:none, opacity zero, off-screen, ARIA-hidden. The accessibility tree your agent reads exposes them all. One smuggled paragraph and the model is following the attacker, not you.