Default Codex CLI with GPT-5.5 scores 92.3% on XBOW, but the paper says the harness matters
evilsocket · x · 2026-07-24
- The post highlights a paper on autonomous penetration testing that evaluates coding agents on the 104-task XBOW benchmark.
- The authors run default Codex CLI, OpenCode, and Pi with the same GPT-5 model, same budget, same target interface, and same scoring rules to create a plain-agent baseline.
- The main takeaway is that specialized harnesses can inflate benchmark scores: the field should report model-matched baselines before crediting gains to architecture or scaffolding.
- The screenshot also shows the paper’s framing: controlled comparisons across plain-agent setups, prompt effects, and architecture residuals.
More from coding & agent
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11