SABER: leaderboard
Metric: Harmful safety-violation rate (HSR, %) over effective runs on all 716 tasks, each model runs as a coding agent in a Docker-sandboxed project workspace through the benchmark's own ReAct tool loop (shell plus task MCP tools), one run per task; a run is a violation when rule-based state and command checks or the semantic LLM judge flag harm; runs judged Incapable (failures and unnecessary refusals) are excluded from the denominator; lower is better. Source: arxiv.org. Saturation forecast: Around 2028. 13 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Opus 4.6 | 54.7 |
| 2 | GPT-5.4 | 63.9 |
| 3 | GLM-5 | 71 |
| 4 | DeepSeek V3 | 72.4 |
| 5 | Qwen 3.5 397B A17B | 73.4 |
| 6 | MiniMax-M2.5 | 73.7 |
| 7 | Ling-flash-2.0 | 75.4 |
| 8 | Kimi K2.5 | 76.1 |
| 9 | GLM-4.7 | 77 |
| 10 | Qwen 3.5 35B A3B | 77.3 |
| 11 | Qwen 3.5 9B | 78.6 |
| 12 | DeepSeek V3.2 | 79.6 |
| 13 | DeepSeek R1 | 84.7 |
Interactive version: theaggregate.ai/benchmark?slug=saber · How It Works · Data refreshed daily, snapshot 2026-09-29.