Skip to content
Standards Coverage

The frameworks name the threat. ATR runs it.

MITRE ATLAS, OWASP, NIST AI RMF, ISO 42001 — six frameworks classify what can go wrong. ATR is the executable layer underneath: detection that fires on a real agent artifact. Every rule carries mappings into all six frameworks, enforced in CI.

How to read this
PINT-format (850 samples)

ATR reaches 65.4% recall on 850 PINT-format adversarial samples, with zero false positives on that corpus's 399 benign samples (ATR 3.5.12, measured 2026-08-15). This is a self-built corpus (deepset + Lakera Gandalf), not Lakera's official private PINT benchmark; only a small subset of rules fire on it, so read it as a prompt-injection-family score rather than overall coverage.

HackAPrompt (4,780 samples)

ATR catches 69.6% of the 4,780 HackAPrompt competition samples (ATR 3.5.0, measured 2026-06-16). The corpus is 100% adversarial with no benign population, so it cannot yield a precision or false-positive figure — do not read it as precision evidence.

Self-test (341 samples)

ATR reaches 96.6% recall with zero false positives on 341 internal self-test samples (ATR 3.5.12, measured 2026-08-15) — a separate corpus from the SKILL.md benchmark, and an in-house one, so it is not out-of-sample evidence.

garak (650 in-the-wild / 3,475 full)

ATR reaches 92.3% recall on garak's in-the-wild jailbreak set (650 prompts), and 57.2% on the full 23-probe garak suite (3,475 prompts) — both at ATR 3.5.12, measured 2026-08-15.

OWASP Agentic
10/10
SAFE-MCP
78/85 (91.8%)
OWASP AST10
7/10
PINT F1
79.1

OWASP Agentic Top 10

10/10 categories, each backed by rules that fire — not a checklist, detections.

ASI01
Agent Goal Hijack
13
STRONG
ASI02
Tool Misuse & Exploitation
11
STRONG
ASI03
Identity & Privilege Abuse
9
STRONG
ASI04
Agentic Supply Chain Vulnerabilities
8
STRONG
ASI05
Unexpected Code Execution / RCE
8
STRONG
ASI06
Memory & Context Poisoning
8
STRONG
ASI07
Insecure Inter-Agent Communication
5
MODERATE
ASI08
Cascading Failures
4
MODERATE
ASI09
Human-Agent Trust Exploitation
5
MODERATE
ASI10
Rogue Agents
7
MODERATE

OWASP Agentic Skills Top 10 (AST10)

8/10 categories with rule coverage. 3 categories are process/meta-level (not pattern-detectable).

AST01
Malicious Skills
7
STRONG
AST02
Supply Chain Compromise
8
STRONG
AST03
Over-Privileged Skills
4
MODERATE
AST04
Insecure Metadata
3
MODERATE
AST05
Unsafe Deserialization
3
MODERATE
AST06
Weak Isolation
3
PARTIAL
AST07
Update Drift
2
PARTIAL
AST08
Poor Scanning
0
GAP (meta-concern)
AST09
No Governance
0
GAP (process-level)
AST10
Cross-Platform Reuse
1
PARTIAL

SAFE-MCP

78 of 85 MCP attack techniques are backed by a detection rule (91.8%) — the remaining 7 are known gaps, stated plainly rather than papered over. Mapping is revised continuously as categories are reconciled.

View full SAFE-MCP mapping on GitHub→

MITRE ATLAS

Every rule's YAML carries a MITRE ATLAS reference — part of ATR's per-rule mapping into six frameworks (ATLAS, OWASP Agentic, OWASP LLM, EU AI Act, NIST AI RMF, ISO 42001). A rule with no mapping does not reach main; CI enforces it. Grouped by tactic in the rule explorer.

Browse rules with MITRE mappings→