REDAgentBench (Codex): leaderboard

Metric: Attack success rate (%; share of valid rollouts judged harmful over 1,661 executable red-teaming cases in five mocked service surfaces and 15 user-, environment- and tool-side attack categories; rule-first hybrid trajectory and state judge with a Qwen3.7-plus backbone; clean evaluation context; Codex agent harness). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 6 models tracked.

Top models

#ModelScore
1GLM-5.2 (Codex)48.12
2Qwen3.7-plus (Codex)54.38
3GPT-5.2 (Codex)62.31
4Qwen-plus-2025-12-01 (Codex)71.81
5Qwen3.5-plus (Codex)75.35
6Kimi K2.6 (Codex)78.51

Interactive version: theaggregate.ai/benchmark?slug=redagentbench-codex · How It Works · Data refreshed daily, snapshot 2026-09-26.