AgentS4D (Claude Code): leaderboard

Metric: Conditional attack success rate (%, cASR): unsafe runs over runs that were unsafe, explicitly defended, or safe after confirmed payload contact, over the 328 risk-injected cases run once in the Claude Code (2.1.201) harness; lower is better. Source: arxiv.org. Saturation forecast: Around 2030. 5 models tracked.

Top models

#ModelScore
1Qwen 3.7 Plus60.8
2MiniMax-M369.42
3GPT-5.571.95
4DeepSeek V4 Pro84.23
5Gemini 3.1 Pro (Preview)91.23

Interactive version: theaggregate.ai/benchmark?slug=agents4d-claude-code · How It Works · Data refreshed daily, snapshot 2026-09-29.