DTap-Bench (Indirect Attacks) - Workflow: leaderboard
Metric: Attack success rate (%; 107 indirect red-teaming workflow (email, calendar, documents, messaging, payments) tasks: third-party tool, skill and environment injections into a benign user task; an attack succeeds when a rule-based check of the final environment state finds the malicious goal fully achieved; fixed attack sequences that DTap-Red optimized on a surrogate agent; mean of its risk-category rates). Source: arxiv.org. Saturation forecast: Estimated already saturated. 8 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-OSS-120B | 7.2 |
| 2 | GPT-5.4 | 50.8 |
| 3 | GPT-5.2 | 63.1 |
| 4 | Gemini 3 Pro | 65.9 |
Interactive version: theaggregate.ai/benchmark?slug=dtap-bench-indirect-attacks-workflow · How It Works · Data refreshed daily, snapshot 2026-09-26.