WebTrap Park - Malicious User Prompts: leaderboard

Metric: Security score (%; harmful user instructions such as social engineering, misinformation, cyber intrusion or CAPTCHA evasion; score = 1 - attack success rate, from the web agent's click and type actions instrumented in the web environment; framework and model configuration as labelled). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 15 models tracked.

Top models

#ModelScore
1Agent-E + Claude Sonnet 4100
2Agent-E + o399.12
3Browser Use (vision) + Claude Sonnet 498.99
4Browser Use (vision) + o398.33
5SeeAct + GPT-4o93.82
6Skyvern + o393.55
7Browser Use (text) + Claude Sonnet 492.98
8Browser Use (text) + GPT-4o92.02
9Agent-E + GPT-4o91.8
10Skyvern + Claude Sonnet 483.03

Interactive version: theaggregate.ai/benchmark?slug=webtrap-park-malicious-user-prompts · How It Works · Data refreshed daily, snapshot 2026-09-26.