Awesome AI AgentsRuntime Analysis Tools

SALT-NLP/PopupAttack

⭐ 52 Python added to this list on 2025-04-19 repository created 2024-11-04

The project "PopupAttack" by SALT-NLP is a code repository accompanying the research paper titled "Attacking Vision-Language Computer Agents via Pop-ups." This work explores vulnerabilities in autonomous agents powered by large vision and language models (VLMs) that perform daily computer tasks such as web browsing and software operation by understanding visual interfaces. The research demonstrates that these VLM agents can be manipulated through adversarial pop-ups—visual distractions that human users typically recognize and ignore but which cause the agents to click on them erroneously, disrupting their intended task execution. The project integrates these adversarial pop-ups into existing agent testing environments like OSWorld and VisualWebArena, achieving an average attack success rate of 86%, significantly reducing the agents' task success rate by 47%. The repository includes code for generating and drawing these adversarial pop-ups, utilities for image processing, and modifications to agent prediction logic to prepare and execute the attacks. It also provides example commands and configurations for running the attacks within the OSWorld and VisualWebArena environments. The project highlights the ineffectiveness of basic defense mechanisms such as instructing agents to ignore pop-ups or adding advertisement notices. The repository contains detailed setup instructions, data for testing, and acknowledges related works and tools that contributed to the research. This project is valuable for researchers and developers interested in the security and robustness of vision-language models in autonomous agents, particularly in understanding and mitigating adversarial attacks in multimodal AI systems.

https://github.com/SALT-NLP/PopupAttack

adversarial-attacksadversarial-pop-upsagent-testingattackautonomous-agentsclaude-3-5-sonnetcomputer-usecomputer-visionimage-processingllm-agentmultimodal-ainatural-language-processingosworldpop-uppop-upsrobustnesssecuritytask-disruptionvision-language-modelvision-language-modelsvisualwebarenavlm

Also in Runtime Analysis Tools

zylon-ai/private-gpt

PrivateGPT is a fully private, offline-capable AI platform that enables users to interact with their documents using Large Language Models through a comprehensive API and user-friendly interface, ensuring data never leaves the user's environment.

vxcontrol/pentagi

PentAGI is a fully autonomous AI-driven penetration testing system that integrates professional security tools, multi-agent AI collaboration, and scalable microservices architecture to deliver comprehensive and automated security assessments.

fortra/impacket

Impacket is a Python library offering low-level programmatic access and implementations for various network protocols, focusing on security research and educational use.

FunnyWolf/Viper

VIPER is a versatile and powerful red team platform that supports adversary simulation and cybersecurity assessments across multiple operating systems, enhanced with AI-driven automation and extensive post-exploitation capabilities.

invariantlabs-ai/mcp-scan

MCP-Scan is a security tool that statically and dynamically scans MCP connections to detect and prevent vulnerabilities like prompt injections, tool poisoning, and cross-origin escalations, offering real-time monitoring and customizable guardrails for enhanced protection.

openrecall/openrecall

OpenRecall is a fully open-source, privacy-focused digital memory tool that captures and makes searchable your digital history through screenshots, supporting Windows, macOS, and Linux with local data storage and advanced semantic search capabilities.

miscusi-peek/cheatengine-mcp-bridge

MCP server that exposes Cheat Engine memory reading, scanning, disassembly and debugging to AI agent clients through roughly 180 tools over a named pipe or TCP relay.

amonapp/amon

Amon is a modern, open-source server monitoring platform designed to help users track and manage server performance and uptime effectively.