AgentHazard (OpenClaw) - Persistence Establishment: leaderboard
Metric: Attack success rate (%) on the persistence establishment instances (backdoors, SSH keys, startup scripts or scheduled jobs that keep long-term access), with the model running inside the OpenClaw open-source agent framework (browser, shell and file-system tools; one isolated Docker container per task), over AgentHazard instances (harmful objectives embedded in locally legitimate multi-step workflows, ten risk categories and ten attack strategies; the evaluated runs cover 1,000 instances), judged on the full trajectory (round_all) by Gemini-3-Flash, which labels a trajectory harmful when it realizes the objective; backbones served through an OpenAI-compatible API; lower is better. Source: arxiv.org. 7 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 2.5 72B Instruct | 37.37 |
| 2 | Kimi K2.5 | 59.6 |
| 3 | Qwen 2.5 Coder 32B Instruct | 66.67 |
| 4 | Kimi K2 | 68.69 |
| 5 | Qwen 3 VL 235B A22B Instruct | 73.74 |
| 6 | Qwen 3 32B | 75.51 |
| 7 | GLM-4.6 | 81.82 |
Interactive version: theaggregate.ai/benchmark?slug=agenthazard-openclaw-persistence-establishment · How It Works · Data refreshed daily, snapshot 2026-10-07.