REDAgentBench (OpenClaw): leaderboard

Metric: Attack success rate (%; share of valid rollouts judged harmful over 1,661 executable red-teaming cases in five mocked service surfaces and 15 user-, environment- and tool-side attack categories; rule-first hybrid trajectory and state judge with a Qwen3.7-plus backbone; clean evaluation context; OpenClaw agent harness). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 6 models tracked.

Top models

#ModelScore
1Qwen3.7-plus (OpenClaw)49.39
2GPT-5.2 (OpenClaw)51.54
3GLM-5.2 (OpenClaw)54.57
4Kimi K2.6 (OpenClaw)73.31
5Qwen3.5-plus (OpenClaw)73.7
6Qwen-plus-2025-12-01 (OpenClaw)78.74

Interactive version: theaggregate.ai/benchmark?slug=redagentbench-openclaw · How It Works · Data refreshed daily, snapshot 2026-09-26.