AgentHazard (Claude Code) - Supply Chain Poisoning: leaderboard

Metric: Attack success rate (%) on the supply chain poisoning instances (malicious changes to dependencies, build scripts, packages or CI/CD workflows), with the model running inside the Claude Code CLI agent (persistent shell, file editing, tool use; restricted shell sessions), over AgentHazard instances (harmful objectives embedded in locally legitimate multi-step workflows, ten risk categories and ten attack strategies; the evaluated runs cover 1,000 instances), judged on the full trajectory (round_all) by Gemini-3-Flash, which labels a trajectory harmful when it realizes the objective; backbones served through an OpenAI-compatible API; lower is better. Source: arxiv.org. 7 models tracked.

Top models

#ModelScore
1Qwen 2.5 72B Instruct16.33
2Kimi K218.37
3Qwen 2.5 Coder 32B Instruct46.94
4Kimi K2.566.33
5GLM-4.676.53
6Qwen 3 VL 235B A22B Instruct76.53

Interactive version: theaggregate.ai/benchmark?slug=agenthazard-claude-code-supply-chain-poisoning · How It Works · Data refreshed daily, snapshot 2026-10-07.