Skills
GUI agents on Android fall to environmental injection 40.4-66.9% of the time across all six agents tested
MobileWorldSafety benchmarks GUI agents against environmental injection attacks embedded in Android apps, using a two-stage evaluation pipeline that combines rule-based verification with LLM-based adjudication specifically to separate safety failures from plain capability failures - a distinction most agent-safety numbers blur. All six tested agents proved highly vulnerable, with attack success rates from 40.4% to 66.9%. Single-source as of this writing, but the methodological point generalizes beyond mobile: if your eval can't tell 'the agent was hijacked' from 'the agent was incompetent', your reported ASR is measuring both.
↳ Follow the thread