REDAgentBench (Codex): leaderboard
Metric: Attack success rate (%; share of valid rollouts judged harmful over 1,661 executable red-teaming cases in five mocked service surfaces and 15 user-, environment- and tool-side attack categories; rule-first hybrid trajectory and state judge with a Qwen3.7-plus backbone; clean evaluation context; Codex agent harness). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GLM-5.2 (Codex) | 48.12 |
| 2 | Qwen3.7-plus (Codex) | 54.38 |
| 3 | GPT-5.2 (Codex) | 62.31 |
| 4 | Qwen-plus-2025-12-01 (Codex) | 71.81 |
| 5 | Qwen3.5-plus (Codex) | 75.35 |
| 6 | Kimi K2.6 (Codex) | 78.51 |
Interactive version: theaggregate.ai/benchmark?slug=redagentbench-codex · How It Works · Data refreshed daily, snapshot 2026-09-26.