uber/ADR

▲ 36 stars today★ 1,889⑂ 194

ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.

About uber/ADR

uber/ADR is an open-source project on GitHub, mainly written in Python. ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber. It currently holds 1,889 stars and 194 forks with 5 open issues, and was last pushed on 2026-10-07 (repository created 2026-04-19).

Project Overview

Git Homed tracks it on the Today's Trending board, currently at rank #86 with 36 new stars today.

GitHub Repository Details

Repository uber/ADR · default branch main · size 15170 KB · watchers 13 · source: GitHub REST API and repository README

README

ADR: Agentic AI Detection and Response

uber/ADR | Trendshift

ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, Codex, GitHub Copilot CLI, and DeepSeek Harness, as well as customer-facing agents such as AI support agents.

ADR is deployed in production at Uber, and the accompanying paper was accepted to MLSys 2026: Paper PDF · Slides PDF

How ADR secures enterprise AI agents

ADR secures enterprise AI agents through five complementary capabilities: discovering unsanctioned AI tools, observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.

1. ADR Discovery: Find the AI tools present on employee endpoints. Inventories installed AI applications, CLI agents, IDE extensions, local model runtimes, and MCP servers, and flags unknown surfaces for review. 2. ADR Observability: Understand what AI agents are doing and why. In production, ADR captures agent intent, tool use, and execution traces across 7+ AI coding tools on macOS, Linux, and Windows, as well as internal automation and customer-facing support agents. 3. ADR Benchmark: Test agent security under realistic enterprise conditions. ADR-Bench includes 300+ tasks, 134 MCP servers, and coverage of all 17 agent attack techniques. 4. ADR Detection: Detect risky agent behavior efficiently. Its two-tier architecture combines high-recall triage with deeper agentic reasoning for suspicious sessions. 5. ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release. Stay tuned.

Repository layout

This repository contains the open-source ADR Discovery, ADR Sensor, ADR-Bench, and ADR Detector described in the paper. The offline ADR Explorer engine, which hardens ADR Detection through pre-deployment red teaming, is not included here.

| Path | ADR component | Description | | -------------------------------------------------- | -------------------------- | ------------------------------------------------------------------------------------ | | Discovery/ | ADR Discovery | Inventory the AI apps, CLI agents, IDE extensions, model runtimes, and MCP servers on an endpoint, and flag unknown surfaces for review | | Sensor/ | ADR Observability | Collect and normalize agent telemetry from Claude Code, Cursor, Codex, GitHub Copilot CLI, DeepSeek Harness, opencode, Claude Desktop, and others | | Detection/ | ADR Benchmark + Detection | Dual-agent detector, 134 MCP servers, 304 benchmark tasks, baselines, figure scripts | | docs/REPRODUCIBILITY.md | Evaluation | Step-by-step workflow to reproduce benchmark detection and paper figures |

Quick start: ADR Detection

git clone https://github.com/uber/ADR
cd ADR/Detection
uv sync
export ANTHROPIC_API_KEY="..." OPENAI_API_KEY="..."

Default detector is adr (ADR dual-agent). For keyless smoke tests, use --detector llamafirewall (see Detection/README.md).

See docs/REPRODUCIBILITY.md for the full evaluation workflow (inflate packed benchmark → run detectors → plot figures).

Component documentation:

ADR Sensor also captures Gemini CLI session journals on macOS, Linux, and Windows, including tool results and nested subagent sessions.

Citation

@inproceedings{li2026adr,
  title={ADR: An Agentic Detection System for Enterprise Agentic AI Security},
  author={Li, Chenning and Hu, Pan and Xu, Justin and Ozbas, Baris and Liu, Olivia and Van, Caroline and Li, Manxue and Zhou, Wei and Alizadeh, Mohammad and Zhang, Pengyu and Sriramadhesikan, KK and Zhang, Ming},
  booktitle={Proceedings of the Ninth Conference on Machine Learning and Systems},
  year={2026}
}

Or use CITATION.cff.

Star History

https://github.com/uber/ADR/blob/HEAD/Star History Chart

License

Apache License 2.0. See LICENSE. Detection/benchmark/agentdojo/ is vendored third-party code under its own LICENSE (MIT).

Data notice

Detection/ includes synthetic benchmark fixtures (fake credentials, emulated environments, prompt-injection scenarios) for defensive security research only. Details: docs/OPEN_SOURCE_REVIEW.md.

GitHub Stars & Activity

1,889Stars
194Forks
5Open issues
PythonLanguage

GitHub Popularity

GitHub stars1,889
Forks194
Open issues5
Primary languagePython
LicenseApache-2.0
Stars gained today36
Created2026-04-19
Last pushed2026-10-07

Trending History

Daily boardrank #86 · ▲ 36 stars

Related GitHub Projects

1

microsoft / markitdown

Python★ 189,010⑂ 14,002▲ 193 stars
→
2

vllm-project / vllm

Python★ 93,340⑂ 23,091▲ 73 stars
→
3

Z4nzu / hackingtool

Python★ 80,393⑂ 9,110▲ 216 stars
→
4

calesthio / OpenMontage

Python★ 64,982⑂ 8,243▲ 375 stars
→
5

ayghri / i-have-adhd

Python★ 54,999⑂ 3,155▲ 620 stars
→
6

anthropics / knowledge-work-plugins

Python★ 27,099⑂ 3,170▲ 764 stars
→
7

smicallef / spiderfoot

Python★ 23,095⑂ 3,711▲ 187 stars
→
8

earthtojake / text-to-cad

Python★ 18,267⑂ 1,817▲ 543 stars
→

More Trending Repositories