WebTrap Park - Malicious Prompt Injection: leaderboard

Metric: Security score (%; instructions injected into page content as visible or invisible form text, ARIA labels or mirrors; score = 1 - attack success rate, from the web agent's click and type actions instrumented in the web environment; framework and model configuration as labelled). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 15 models tracked.

Top models

#ModelScore
1Agent-E + GPT-4o79.17
2SeeAct + GPT-4o73.25
3Skyvern + Claude Sonnet 471.6
4SeeAct + Qwen-VL-Max71.35
5Browser Use (text) + GPT-4o71.27
6Skyvern + GPT-4o71.16
7Browser Use (text) + Qwen2.5-72B-Instruct69.3
8Browser Use (vision) + Claude Sonnet 467
9Agent-E + o366.45
10Browser Use (text) + DeepSeek-V365.79

Interactive version: theaggregate.ai/benchmark?slug=webtrap-park-malicious-prompt-injection · How It Works · Data refreshed daily, snapshot 2026-09-26.