Benchmark Radar
AI BENCHMARK PROFILE

AgentRedBench

General AIKnowledge & Reasoning

AgentRedBench evaluates LLM agents against indirect prompt injection and underspecified-authorization attacks across 24 enterprise SaaS integrations. It defines 215 attack scenarios with immutable versioning, and tracks attack success rate (ASR) for models and defenses. Open-source codebase and schemas enable replay.

Released
2026-06-01
Readiness
Paper only
Primary field
General AI

Why it matters

Prior agent-security benchmarks cover limited integrations with static payloads, understating real-world exploitability. AgentRedBench provides a dynamic, maintainer-mediated evaluation to compare model and guard-rail effectiveness against evolving injection threats, supporting procurement and hardening decisions.

Motivation

Indirect prompt injection in tool-use agents is a concrete production threat: LLM agents read from integrations (third-party services such as Gmail, Salesforce, or Jira accessed through tool calls) whose response content the user neither writes nor controls.

Primary resources

Benchmark Radar records only publicly supported details and links back to primary sources for verification.