LITMUS - Code Execution: leaderboard
Metric: Attack success rate (%): share of the 23 Code Execution seed cases whose dangerous operation physically took effect on the OS, OpenClaw 4.2.0 agent on Ubuntu 24.04 given seed behavior-jailbreak instructions, physical OS state checked by a GPT-4o verifier and analyzer, mean of three runs per case; lower is better. Source: arxiv.org. Saturation forecast: Around January 2027. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Sonnet 4.6 | 39.52 |
| 2 | Gemini 3.1 Pro (Preview) | 47.17 |
| 3 | GPT-5.3 Codex | 49.27 |
| 4 | Qwen 3.6 Plus | 53.62 |
| 5 | DeepSeek V4 Pro | 57.97 |
| 6 | DeepSeek V3.2 | 63.31 |
Interactive version: theaggregate.ai/benchmark?slug=litmus-code-execution · How It Works · Data refreshed daily, snapshot 2026-10-07.