Agent safety and security / Benchmark leaderboard

AgentDojo

Indirect prompt-injection attacks against useful tool workflows.

No published company result yet.

This benchmark is in the research directory. Its task package, adapter and grading protocol need qualification before a hosted run can be offered.

Arrange an evaluation for your company →

What this benchmark measures

Metrics

Attack success and benign task utility, reported together.

Execution requirements

Agent + defensive product in the same benchmark workflow.

Scope and limitations

Refusing every task is not a useful defense. Compare attack resilience at preserved task utility.

Evaluation availability

Catalog entry. Request a managed evaluation to qualify your agent interface and the benchmark’s native grading requirements.

Sources and company fit

Companies whose products may fit

Research recommendations based on product capabilities. These companies have not necessarily run this benchmark or integrated with Blobfish.

Compatibility notes for each company

Anthropic: Capability-aligned; adapter/access to qualify

Browser Use: Capability-aligned; adapter/access to qualify

Glean: Capability-aligned; adapter/access to qualify

HiddenLayer: Capability-aligned; adapter/access to qualify

Lakera: Capability-aligned; adapter/access to qualify

OpenAI: Capability-aligned; adapter/access to qualify

Prompt Security: Capability-aligned; adapter/access to qualify

Protect AI: Capability-aligned; adapter/access to qualify

Salesforce: Product-specific adapter / qualified access