All 25 public ARC-AGI-3 games downloaded to a studio test machine in one process, on one anonymous key, in under a minute. The smallest is 777 lines of Python. The largest is 41,463. Between them they hold exactly 183 levels, which is the number every “100% on the public set” claim is counting, NVIDIA’s included.
Here is what the 25 ARC-AGI-3 games look like from the outside of the source, before anyone plays them.
How big each ARC-AGI-3 game is in lines of code
The survey script called make() on every id the API listed, read the downloaded file and its metadata.json, sent a RESET, and recorded what came back. The full table, sorted by size:
| Game | Levels | Lines | Actions offered | Human baseline, level 1 |
|---|---|---|---|---|
| ka59 | 7 | 41,463 | 1 2 3 4 6 | 28 |
| lp85 | 8 | 21,451 | 6 | 17 |
| dc22 | 6 | 10,892 | 1 2 3 4 6 | 59 |
| lf52 | 10 | 5,872 | 1 2 3 4 6 7 | 32 |
| bp35 | 9 | 4,565 | 3 4 6 7 | 21 |
| g50t | 7 | 2,855 | 1 2 3 4 5 | 78 |
| sc25 | 6 | 2,750 | 1 2 3 4 6 | 36 |
| tn36 | 7 | 2,647 | 6 | 32 |
| ft09 | 6 | 2,520 | 6 | 43 |
| s5i5 | 8 | 2,247 | 6 | 20 |
| su15 | 9 | 2,172 | 6 7 | 22 |
| re86 | 8 | 2,158 | 1 2 3 4 5 | 26 |
| vc33 | 7 | 2,124 | 6 | 7 |
| ls20 | 7 | 2,060 | 1 2 3 4 | 22 |
| r11l | 6 | 1,849 | 6 | 22 |
| ar25 | 8 | 1,847 | 1 2 3 4 5 6 7 | 32 |
| tu93 | 9 | 1,272 | 1 2 3 4 | 19 |
| wa30 | 9 | 1,254 | 1 2 3 4 5 | 71 |
| cn04 | 6 | 1,182 | 1 2 3 4 5 6 | 29 |
| sb26 | 8 | 1,146 | 5 6 7 | 18 |
| tr87 | 6 | 1,121 | 1 2 3 4 | 54 |
| sk48 | 8 | 982 | 1 2 3 4 6 7 | 61 |
| m0r0 | 6 | 924 | 1 2 3 4 5 6 | 30 |
| sp80 | 6 | 868 | 1 2 3 4 5 6 | 39 |
| cd82 | 6 | 777 | 1 2 3 4 5 6 | 55 |
The median game is 2,124 lines. Two are outliers by an order of magnitude: ka59 at 41,463 lines and 813 KB on disk, and lp85 at 21,451. Neither has more levels than the others. Line count in these files is mostly sprite data, pixel arrays written out one row at a time, so a big file is a game with a lot of distinct pieces, not a game with a lot of rules. The rules are in the scrambled functions, and those are a small fraction of any file.
Which actions each ARC-AGI-3 game actually exposes
The engine defines seven actions plus reset, but no game offers all seven. The 25 games use ten distinct subsets. Six of them, lp85, tn36, ft09, s5i5, vc33 and r11l, expose only ACTION6, the click on a cell, so the entire game is pointing. Three, ls20, tu93 and tr87, are pure four key games. One, ar25, offers everything.

Action subsets across the 25 public games. Yellow: the six games that are click only. Read from the first frame after RESET, 4 September 2026.
That split is the first thing to check before building a harness, because the two kinds of game need different agents. A keyboard game has at most seven legal moves per turn. A click game has up to 4,096, one per cell, and an agent that treats ACTION6 as one action rather than a family of them will never do anything useful in a quarter of the public set. The technical report describes the action space as a subset per environment for exactly this reason: “Each environment offers a different action space.”
ACTION7, the undo, appears in only six games. ACTION5 appears in nine. Any agent that assumes a fixed action list will be wrong on most of the set.
How many levels and colours each ARC-AGI-3 game uses
Levels run from six to ten per game, 183 in total, and every game meets the report’s stated minimum of six. The first frame of each game uses between four and eleven of the sixteen available colours, with lp85 the busiest at eleven and m0r0 the sparsest at four. The full sixteen never appear at once on a first frame.
The human baselines tell you how the levels are meant to feel. Level one takes a first time human between 7 moves (vc33) and 78 (g50t), median 30. Across all 183 levels the baseline runs from 6 to 578, with the top end in dc22, whose sixth level takes a person 578 actions. Every one of these numbers is in the game’s own metadata, so the score any agent gets is computable before you have played a single turn.
Which ARC-AGI-3 games random play can clear
The same survey pressed 60,000 random legal actions against each game, resetting after every game over, with random coordinates for click actions. It cleared level one in 12 of the 25 games, and reached level two in exactly two, tu93 and ar25. It never got further.
Where it did clear a level, it did so at a cost that makes the point about scoring. sp80 fell at 288 actions against a human 39. r11l at 383 against 22. ls20 needed 40,699 against 22, and tr87 needed 59,536 against 54. Under the squared efficiency metric those are scores of a few points at best and effectively zero at worst, for levels that were genuinely completed.
The death count is the other half of the story. Random play died 20 times in 60,000 actions on lp85 and 3,330 times on r11l, with a median of 594. Some games have almost no failure state and some kill a wandering agent every eighteen moves. An agent needs to learn which kind it is in before it learns anything else, and the first RESET after a game over is where most first agents silently break.
What the 25 ARC-AGI-3 games say about the private 110
Less than you would like. The report is direct that the public set is “intentionally easier for both humans and AI, with a stronger emphasis on clarity and fun”, and that it “does not comprehensively represent the mechanics found in the private” sets.
So the table above is a map of the training ground, not the exam. What transfers is structural: games are 6 to 10 levels, action sets vary per game and must be read from the frame, click games and key games are different problems, and the human baseline per level is the only number that matters. What does not transfer is any particular mechanic, and the private games were built specifically so that it would not.
An agent that handles all ten action subsets, treats ACTION6 as a space rather than a button, checks state after every step, and never assumes it knows a game from its id is ready for the public 25. Whether it is ready for the other 110 is the question the leaderboard exists to answer, and nothing on this disk can.
