ADR: Secure and Monitor Enterprise AI Agents

Summary
ADR is an enterprise security toolkit for discovering AI tools, collecting agent activity, benchmarking defenses, and detecting risky behavior. It is aimed at security teams evaluating or monitoring AI agents across employee endpoints and customer-facing systems.
At a glance
- Language
- Python
- License
- Apache-2.0
- Stars
- 1.6k
- Forks
- 172
- Added to OSRepos
- August 14, 2026
- Last analyzed
- October 3, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
ADR helps organizations understand which AI agents and related tools are present, observe their activity, and identify security risks such as prompt injection. Its open-source components cover endpoint discovery, telemetry collection, security benchmarks, and detection, addressing the challenge of securing agents used across varied tools and workflows.
The project is intended for enterprise security and engineering teams that need to assess agent behavior or reproduce security evaluations. The repository does not include ADR Prevention or the ADR Explorer red-teaming engine.
Key Features
- Discovers AI applications, command-line agents, IDE extensions, local model runtimes, and MCP servers on endpoints.
- Collects and normalizes agent telemetry, including intent, tool use, and execution traces.
- Supports telemetry from multiple coding agents and platforms, including Claude Code, Cursor, Codex, and Gemini CLI.
- Includes ADR-Bench with benchmark tasks and MCP servers for evaluating agent security.
- Provides a dual-agent detector with a high-recall triage stage and deeper reasoning for suspicious sessions.
- Includes a keyless smoke-test option using the
llamafirewalldetector.
Use Cases
- Security teams inventorying AI tools on employee devices and identifying unsanctioned applications or MCP servers.
- Platform teams investigating agent sessions by reviewing normalized activity and tool-use traces.
- AI security researchers comparing detection approaches against realistic benchmark tasks.
- Enterprise engineering teams reproducing the paper's benchmark evaluations and figures.
Project Facts
- Language: Python
- License: Apache-2.0
- Stars: 1.6k
- Forks: 172
- Topics: agent-security, ai-agents, ai-security, benchmark, claude, claude-code, codex, cursor, llm-security, mcp, model-context-protocol, prompt-injection, threat-detection
- Archived: No
Getting Started
git clone https://github.com/uber/ADR
cd ADR/Detection
uv sync
The default detector requires API keys. See the Detection README for setup, and the reproducibility guide for the evaluation workflow. Component-specific instructions are in the Discovery, Sensor, and Detection directories.
Alternatives
- giskard-oss: Giskard focuses on repeatable vulnerability probes and safety tests for AI systems, while ADR also targets tool discovery and ongoing agent activity monitoring.
Considerations
- The default detector needs API keys for Anthropic and OpenAI. A keyless smoke test is available with
--detector llamafirewall. - Prevention and ADR Explorer are not included in the open-source repository.
- The benchmark fixtures are synthetic and intended for defensive security research.
- The repository contains vendored third-party AgentDojo code under its own MIT license; review its license alongside the project's Apache-2.0 license.
Source repository
Open the original repository on GitHub.
22 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

web-design: A Claude Code SKILL for Spec-First Web Page Design
October 3, 2026
The web-design project is a Claude Code SKILL designed to streamline the creation of beautiful and consistent web pages. It emphasizes a 'spec first, code second' approach, ensuring design principles are established before development begins. This tool helps generate UI, visuals, motion, and responsiveness that are consistent across pages and easily editable.

OOMWOO: Build Your Own Open-Source, Hackable Robot Vacuum Cleaner
October 2, 2026
OOMWOO is an ambitious open-source project enabling users to build their own robot vacuum cleaner using Raspberry Pi, 3D printing, and ROS2. It emphasizes local operation, hackability, and integration with Home Assistant, providing a high-quality, customizable home appliance. This project aims to deliver a fully open hardware, software, and firmware solution for autonomous home cleaning.

Shepherd: Reversible Execution Traces for Programmable Meta-Agents
October 2, 2026
Shepherd is a Python runtime substrate designed for agent work requiring inspection, reversibility, and supervision. It records agent runs as durable, inspectable execution traces, enabling meta-agents to observe, fork, replay, and revert any operation. This framework couples agents and environments using a copy-on-write fork, offering significant performance benefits and robust permission enforcement.

Agent Anvil: CI-First Evaluation Harness for Tool-Using AI Agents
October 1, 2026
Agent Anvil is a robust, CI-first evaluation harness designed for AI agents that utilize tools. It meticulously runs scenario suites, captures detailed traces of agent behavior, and provides semantic grading to identify issues. The platform excels at clustering failures and suggesting concrete fixes for prompts, tools, and guardrails, ensuring agents behave safely and effectively.