Skip to content

Sigma is for SIEM. YARA is for malware.

ATR is for AI agents.

Built so a rule written in Taipei catches an attack first reported in Seattle — without anyone reinventing the rule format.

An open, versioned, machine-readable detection rule format for AI agent security threats. Any conforming engine can evaluate it. Community-maintained, MIT licensed.

819 rules·10 categories·92.3% garak recall
Standards bodies:MISP / CIRCL·OWASP·NIST AI RMF (OSCAL)·OpenTelemetry
Merged upstream:Microsoft AGT·Cisco AI Defense·Gen Digital Sage
Why a new standard

Endpoint detection standards cannot see AI agent behavior.

Old era
Sigma · YARA · CVE

Built for endpoint event logs, file binaries, and software vulnerability IDs. They watch code, not intent.

New surface
AI Agent behavior

Prompt injection, tool poisoning, skill compromise, context exfiltration — attacks live at the prompt / tool call / skill layer, not at process / file / network.

New standard
ATR

Vendor-neutral, machine-readable behavioral detection rules. Watches what an agent does, not just what it runs. Any conforming engine can evaluate it. MIT forever. Community governed.

Before Sigma became the open standard for SIEM detection in 2017, every SOC wrote its own rules. Before CVE in 1999, every vendor numbered its own vulnerabilities. The detection layer for the AI agent era sits in the same position right now — not yet standardized. ATR fills the gap.

000,000
agent skills and MCP definitions scanned — across five public registries
0,000

skills flagged. The flags concentrate heavily in a handful of publisher accounts, pointing at coordinated malware campaigns.

hightower6eu
354
skills published by this account
Solana / Google Workspace disguise
sakaen736jih
212
skills published by this account
C2 server at 91.92.242.30
52yuanchangxing
137
skills published by this account
Fake dev tools + npm typosquatting

ATR found these accounts while scanning 101,280 agent skills and MCP server definitions across five sources — ClawHub, OpenClaw, Skills.sh, Hermes, and an MCP registry index (engine v2.0.0, 2026-04-13). 1,434 items were flagged. These accounts were adjudicated account-wide as known malware campaigns — publisher-level attribution rather than per-file analysis; flagged items were blacklisted and reported to NousResearch.

What ATR Detects

10 threat categories. 819 rules. Real CVEs.

Prompt Injection
251 rules

Hijacking agent behavior through crafted inputs

Context Exfiltration
133 rules

Stealing conversation context and sensitive data

Tool Poisoning
113 rules

Poisoned tool descriptions and malicious tool responses

Agent Manipulation
108 rules

Social engineering and behavioral manipulation of agents

Privilege Escalation
76 rules

Unauthorized elevation of agent capabilities

Skill Compromise
52 rules

Malicious or vulnerable MCP skills and SKILL.md

Model Abuse
41 rules

Misusing model capabilities — jailbreaks, harmful generation, resource abuse

Excessive Autonomy
39 rules

Agents exceeding intended operational boundaries

Data Poisoning
9 rules

Corrupting training data, memory, or retrieval sources to bias agent behavior

Model Security
4 rules

Attacks on the model itself — extraction, inversion, adversarial inputs

Adopted by

Security teams consume ATR as an upstream rule source, merged into their own public repos.

Microsoft AGT

PR #908 + #1277 merged · 287 rules (at PR time) + weekly auto-sync

View PR →

Cisco AI Defense

PR #79 + #99 merged · rule pack in the open-source skill-scanner repo

View PR →

Gen Digital Sage

PR #33 merged · agentic-AI risk-scoring layer at the Norton / Avast / LifeLock parent

View PR →
Production loop · 2h 16m

Microsoft's autonomous AI engineer opened a PR assuming ATR coverage existed — and the assumption was correct.

On 2026-05-11, the Copilot SWE Agent opened AGT#1981 for two Semantic Kernel CVEs with regression fixtures presuming ATR detection. Rules were validated and published to npm within 2h 16m. Not a manually arranged integration.

View AGT#1981 →
4
merged upstream
Microsoft, Cisco, Gen Digital
819
detection rules
across 10 categories
101,280
skills scanned
across registries
26/36
ecosystem PRs
merged
A living standard

Every attack makes everyone safer.

A red-team mega-scan pipeline and a CVE-ingestion pipeline run daily: when the semantic layer catches a novel attack, it crystallizes into a regex rule and flows back into the standard — turning a 500ms inference into a 5ms pattern match. Auto-crystallization grew the standard from 462 to 819 rules, all shipped in npm agent-threat-rules@4.1.3.

But growth was never the point — honesty about precision is. v3.5.0 introduced detection lanes: every rule declares a maturity, and the consumer decides how far to trust it. The enforce lane fires only the most mature rules; the default hunt lane runs everything as advisory. False-positive rates are reported lane by lane, never as a single flattering number — and the per-lane figures previously published here are withdrawn pending re-measurement, because the basis they were measured on did not hold up. Withdrawing a number you can no longer stand behind is the same discipline as publishing your worst one.

agent-threat-rules@4.1.3·819 rules·CVE-ingest + crystallize pipelines run daily·standard regenerated 2026-09-14
Detect1/5
Global Sensors

Endpoints report suspicious patterns via ATR Reporter

More endpoints = more data = stronger rules
OWASP Agentic
10/10
Full coverage
SAFE-MCP
91.8%
78/85 techniques
OWASP AST10
7/10
3 are process-level
PINT-format F1
79.1
self-built 850-sample corpus (not Lakera's official PINT)

Frameworks tell you threats exist. ATR tells you how to detect them. ATR is to MITRE ATLAS what Sigma rules are to ATT&CK — today mapping 34 of 101 official ATLAS techniques (v5.6.0), concentrated on the agent-native surface rather than padded for breadth.

Integrate ATR.

One command. Instant results.
$ npx agent-threat-rules scan .
# results
3 SKILL.md scanned
12 tool descriptions checked
1 CRITICAL: credential theft
rule ATR-2026-00121
Done in 47ms.

TypeScript, Python, Raw YAML, SIEM converters — four integration paths, one ruleset. MIT forever, no license to negotiate, evaluated by any conforming engine.