by Yuxuan2003
GUI / Computer-Use / Browser Agent 安全论文清单 —— 按攻防轴组织,每篇附中文简介
Unlocks once the catalog security scan passes (runs nightly).
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
# Add to your Claude Code skills
git clone https://github.com/Yuxuan2003/Awesome-GUI-Agent-SecurityGuides for using ai agents skills like Awesome-GUI-Agent-Security.
English | 简体中文
A curated list of papers on GUI / Computer-Use / Browser Agent security — organized by attack surface and defense layer, not by runtime environment.
This page is the index — one line per paper. Each section links to a page with a 3–5 sentence summary per paper.
Scope: papers whose primary subject is a GUI / computer-use / browser / mobile agent, with a security contribution. Not included: general LLM/agent security that only uses GUI agents as a testbed · agents for security work (pentest, CTF) · pure capability work.
Most GUI agent lists split papers by runtime environment (Web / Mobile / Desktop), which scatters a single attack class across sections: multi-step indirect injection lands under Desktop, efficiency backdoors under Mobile, pop-up attacks under both Web and Desktop. Answering "what visual-layer attacks exist?" means reading every section.
Here the primary axis is attack vector and defense intervention point. Runtime environment is a cross-cutting tag, used as a primary dimension only inside the benchmarks chapter.
Browse by environment: Web | Mobile | Desktop | Cross-env
Surveys, SoKs, and mappings onto threat taxonomies such as OWASP ASI and MITRE ATLAS · Summaries →
Organized by attack vector and entry point, not by runtime environment
Injection carried by external content: web pages, documents, email · Summaries →
Adversarial patches, pop-up lures, typographic attacks, screenshot poisoning · Summaries →
UI element injection, accessibility tree, spoofed notifications, overlays · Summaries →
OS-level escalation, cross-app privilege abuse, permission-dialog manipulation, TOCTOU · Summaries →
Credential theft, PII leakage, contextual-integrity violations, oversharing · Summaries →
Grounding backdoors, efficiency backdoors, memory poisoning · Summaries →
Awesome-GUI-Agent-Security is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Yuxuan2003. GUI / Computer-Use / Browser Agent 安全论文清单 —— 按攻防轴组织,每篇附中文简介. It has 58 GitHub stars.
Awesome-GUI-Agent-Security's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/Yuxuan2003/Awesome-GUI-Agent-Security" and add it to your Claude Code skills directory (see the Installation section above).
Awesome-GUI-Agent-Security is primarily written in Python. It is open-source under Yuxuan2003 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Awesome-GUI-Agent-Security against similar tools.
No comments yet. Be the first to share your thoughts!