Agents are functional long before they are secure. endor labs benchmarked the top coding harnesses…
agents are functional long before they are secure. endor labs benchmarked the top coding harnesses on vulnerable codebases and claude code with fable 5.1 finished 87.2% of tasks but only 37.4% without introducing new security holes.
the gap between working code and safe code is the actual capability curve.
Context
Endor Labs' post, published 9 April 2026 and updated 4 September 2026, reports Claude Code with Fable 5.1 at 87.2 percent FuncPass and 37.4 percent SecPass. Its research page defines FuncPass as passing the task's functional tests and SecPass as also passing security tests. The benchmark, the Agent Security League, is built on Carnegie Mellon's SusVibes with 200 tasks from 108 open-source Python projects across 77 CWE classes.
This is Endor's own vendor benchmark, Python only, with figures for one harness and model pair. SecPass is a pass on security tests and not a count of newly introduced holes. The benchmark page now shows 85.2 percent as the top functional score for Claude Code with Fable 5.1 and 37.4 percent as the top security score for Claude Code with Fable 5.5, a later board; it is not a refutation and which configuration produced which was not reconciled. Scores are not merged across harnesses. That the gap is the real capability curve is the author's take.
Watch next
- Independent replication and the board's configuration changes.
Sources
- Fable 5.1 takes the top spot (Endor Labs)endorlabs.com
- AI code security benchmark (Endor Labs)endorlabs.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 06:48 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →