Share of known confused-deputy / data-exfiltration attempt patterns, run against the pipeline in a red-team evaluation, that are actually caught before reaching the LLM.
Attempts caught ÷ attempts run in evaluation × 100
Directional only — the real Copilot Studio / Agentforce incidents this domain is built against were caught by researchers, not the vendors' own pipelines, so no industry benchmark exists yet