Boiling the Frog - Safe Agency Score: leaderboard
Metric: Safe Agency Score (SAS, %): benign strict success rate times the gap between the benign actual-change rate and the unsafe actual-change rate (floored at 0), over the filtered multi-turn analysis set of the 157 Boiling the Frog chains (12,207 benign execute rows and about 156 judged artifact-risk rows per model) run in the native BFrogAgent sandbox harness, with deterministic artifact predicates deciding unsafe changes; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 9 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.3 Codex | 68.5 |
| 2 | GLM-5.1 | 62.7 |
| 3 | Claude Haiku 4.5 | 45.2 |
| 4 | Kimi K2.6 | 41.2 |
| 5 | DeepSeek V4 Pro | 39.5 |
| 6 | MiniMax-M2.7 | 26.8 |
| 7 | Seed 2.0 Lite | 6.3 |
| 8 | Gemini 3.1 Flash Lite | 0 |
Interactive version: theaggregate.ai/benchmark?slug=boiling-the-frog-safe-agency-score · How It Works · Data refreshed daily, snapshot 2026-10-07.