Splitting one web agent into a multi-agent crew opens an attack that is inert against single agents: 80% success via a cross-delegation "Telephone Loop"
WebMASLab holds the user task, tool surface, and browser substrate fixed and varies only the architecture, isolating what role decomposition itself costs you in security. The novel Telephone Loop attack exploits cross-agent delegation to create cyclical task loops; it has no effect on single-agent setups but compromises the multi-agent version of three of four frontier models tested (Claude Sonnet 4.5, GPT-5.2, GPT-5.4), averaging 80% success at baseline with 0% detection — only Claude Sonnet 4.6 resisted, at a 92% detection rate. Defenses did not generalize: prompt-hardening cut one model's attack success rate from 100% to 8% while barely moving the others, and lifted detection to just 33% for one. The takeaway for anyone fanning work out to sub-agents is that specialization is an architectural risk decision, not only a performance one.
↳ Follow the thread