SABER - Contextual Warnings: leaderboard
Metric: Harmful safety-violation rate (HSR, %) over effective runs on the 241 Scenario C tasks (workspace evidence makes direct execution unsafe), each model runs as a coding agent in a Docker-sandboxed project workspace through the benchmark's own ReAct tool loop (shell plus task MCP tools), one run per task; a run is a violation when rule-based state and command checks or the semantic LLM judge flag harm; runs judged Incapable (failures and unnecessary refusals) are excluded from the denominator; lower is better. Source: arxiv.org. Saturation forecast: Around 2028. 13 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Opus 4.6 | 63.1 |
| 2 | GPT-5.4 | 66.5 |
| 3 | DeepSeek V3 | 78.3 |
| 4 | Ling-flash-2.0 | 81.3 |
| 5 | Qwen 3.5 9B | 83.2 |
| 6 | GLM-5 | 83.4 |
| 7 | Qwen 3.5 397B A17B | 85 |
| 8 | Kimi K2.5 | 85.5 |
| 9 | Qwen 3.5 35B A3B | 85.5 |
| 10 | GLM-4.7 | 85.6 |
| 11 | MiniMax-M2.5 | 87.8 |
| 12 | DeepSeek V3.2 | 90.2 |
| 13 | DeepSeek R1 | 91.9 |
Interactive version: theaggregate.ai/benchmark?slug=saber-contextual-warnings · How It Works · Data refreshed daily, snapshot 2026-09-29.