BLXBenchBLXBench UI
blxbench

Benchmark

Misc

DocsOur TestsPassSponsor / Partnership
DocsOur TestsPassSponsor / Partnership
BLXBenchBLXBench UI
blxbench

Benchmark

Suite

Misc

DocsOur TestsPassSponsor / Partnership
DocsOur TestsPassSponsor / Partnership
  1. Home
  2. Our Tests
  3. Sec-Session-Replay-Token-Binding
blxbench

Test fixture

Sec-Session-Replay-Token-Binding

Securityv2 — Resiliencehardscorer: rubric_json_metrics

Secure code changes, vulnerability recognition, and safe defaults.

How it is scored

The model receives the prompt (and optional system message). The run uses scorer rubric_json_metrics with the JSON configuration below. Pass/fail and partial credit are determined entirely by that scorer against the model output; no human grading.

User prompt
Return JSON only with keys verdict, risk, mitigation. Bearer session tokens remain valid after theft because there is no replay detection, token rotation, or device binding for high-risk actions.
Scorer config
{
  "metrics": {
    "correct": {
      "checks": [
        {
          "contains": [
            "session replay"
          ]
        },
        {
          "contains": [
            "bearer token"
          ]
        },
        {
          "contains": [
            "theft"
          ]
        }
      ]
    },
    "hidden": {
      "checks": [
        {
          "contains": [
            "rotation"
          ]
        },
        {
          "contains": [
            "device binding"
          ]
        },
        {
          "contains": [
            "step-up"
          ]
        }
      ]
    }
  }
}
Run parameters

temperature

0

max_tokens

560

timeout (s)

120

type

scored

file

sec-session-replay-token-binding.json

← PreviousSec-Session-Fixation-Detector
|
Next →Sec-Sql-Injection-Detector

BLXBench

Community driven leaderboardPublic benchmark runner — run in your environment, share results with the community.

© 2026 BLXBench by bitslix.com

ProvenanceAggregated from user runs
Scope41 / 11 / 490
Latestrun_3d5451 / 459 / $1.75
TermsPrivacy