WebTrap Park - Malicious User Prompts: leaderboard
Metric: Security score (%; harmful user instructions such as social engineering, misinformation, cyber intrusion or CAPTCHA evasion; score = 1 - attack success rate, from the web agent's click and type actions instrumented in the web environment; framework and model configuration as labelled). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 15 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Agent-E + Claude Sonnet 4 | 100 |
| 2 | Agent-E + o3 | 99.12 |
| 3 | Browser Use (vision) + Claude Sonnet 4 | 98.99 |
| 4 | Browser Use (vision) + o3 | 98.33 |
| 5 | SeeAct + GPT-4o | 93.82 |
| 6 | Skyvern + o3 | 93.55 |
| 7 | Browser Use (text) + Claude Sonnet 4 | 92.98 |
| 8 | Browser Use (text) + GPT-4o | 92.02 |
| 9 | Agent-E + GPT-4o | 91.8 |
| 10 | Skyvern + Claude Sonnet 4 | 83.03 |
Interactive version: theaggregate.ai/benchmark?slug=webtrap-park-malicious-user-prompts · How It Works · Data refreshed daily, snapshot 2026-09-26.