No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by SALT-NLP · Agent Tool · ★ 52
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is PopupAttack safe to install? View the security audit →
Attacking Vision-Language Computer Agents via Pop-ups Yanzhe Zhang, Tao Yu, Diyi Yang Overview Autonomous agents powered by large vision and language models (VLM) have demonstrated significant potential in completing daily computer tasks, such as browsing the web to book travel and operating desktop software, which requires agents to understand these interfaces. Despite such visual inputs becoming more integrated into agentic applications, what types of risks and attacks exist around them still remain unclear. In this work, we demonstrate that VLM agents can be easily attacked by a set of carefully designed adversarial pop-ups, which human users would typically recognize and ignore. This distraction leads agents to click these pop-ups instead of performing the tasks as usual. Integrating these pop-ups into existing agent testing environments like OSWorld and VisualWebArena leads to an attack success rate (the frequency of the agent clicking the pop-ups) of 86% on average and decreases the task success rate by 47%. Basic defense techniques such as asking the agent to ignore pop-ups or including an advertisement notice, are ineffective against the attack.
| Stars | 52 |
| Forks | 3 |
| Language | Python |
| Category | Agent Tool |
| Quality Score | 64.3345722823544/100 |
| Open Issues | 1 |
| Last Updated | 2024-12-23 |
| Created | 2024-11-04 |
| Platforms | claude-code, python |
| Est. Tokens | ~13278k |
Looking for a PopupAttack alternative? If you're comparing PopupAttack with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Auto-Use Computer Use — drives your OS, browser, scours the web, writes your code. One agent, end to end.
A fully-featured, GUI-powered local LLM Agent sandbox with complete MCP protocol support. Features both CLI
NEWTON: Agentic Planning for Physically Grounded Video Generation
基于多模态视觉感知与 LLM Agent 的 macOS 微信自动化框架 | Visual RPA for WeChat
[CVPR 2025 🔥]A Large Multimodal Model for Pixel-Level Visual Grounding in Videos
OmniAgent (ICML 2026): the first native omni-modal agent for active video perception — a 7B agent that beats Q
Explore other popular agent tool tools:
PopupAttack is Code repo for the paper: Attacking Vision-Language Computer Agents via Pop-ups. It is categorized as a Agent Tool with 52 GitHub stars.
PopupAttack is primarily written in Python. It covers topics such as attack, claude-3-5-sonnet, computer-use.
You can find installation instructions and usage details in the PopupAttack GitHub repository at github.com/SALT-NLP/PopupAttack. The project has 52 stars and 3 forks, indicating an active community.
The top alternatives to PopupAttack on Agent Skills Hub include Auto-Use, EdgeBox, NEWTON. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: