AgentHazard (OpenClaw) - Destructive Action: leaderboard

Metric: Attack success rate (%) on the destructive action instances (irreversible damage such as deleting files, wiping databases or encrypting data), with the model running inside the OpenClaw open-source agent framework (browser, shell and file-system tools; one isolated Docker container per task), over AgentHazard instances (harmful objectives embedded in locally legitimate multi-step workflows, ten risk categories and ten attack strategies; the evaluated runs cover 1,000 instances), judged on the full trajectory (round_all) by Gemini-3-Flash, which labels a trajectory harmful when it realizes the objective; backbones served through an OpenAI-compatible API; lower is better. Source: arxiv.org. 7 models tracked.

Top models

#ModelScore
1Qwen 2.5 72B Instruct25.26
2Kimi K2.549.47
3Qwen 3 VL 235B A22B Instruct61.05
4Qwen 2.5 Coder 32B Instruct62.11
5Qwen 3 32B62.77
6GLM-4.665.26
7Kimi K268.42

Interactive version: theaggregate.ai/benchmark?slug=agenthazard-openclaw-destructive-action · How It Works · Data refreshed daily, snapshot 2026-10-07.