Tool

ADR

ADR is Uber's open-source toolkit for observing AI agent activity, benchmarking security defenses, and detecting risky behavior with contextual reasoning.

Quick verdict: ADR is one of the more interesting open-source projects for teams trying to understand and test the security of AI agents. Uber built it around real enterprise agent activity, then released a sensor, a security benchmark, and a two-stage detector. It is practical for security engineering and research, but the benchmark is intentionally not a production-ready appliance.

ADR stands for Agentic AI Detection and Response. The project focuses on the gap between ordinary endpoint telemetry and the richer context needed to explain why an agent read a file, called an MCP tool, or sent data somewhere. Its accompanying paper was accepted at MLSys 2026, and the public repository is licensed under Apache-2.0.

What is ADR?

ADR is a security toolkit for observing and evaluating AI agent behavior. The open-source release has three useful pieces. ADR Sensor reconstructs sessions from local logs created by tools such as Claude Code, Cursor, Cline, Codex, Warp, and Claude Desktop Agent Mode. ADR-Bench provides realistic benign and malicious tasks backed by MCP servers. The detector first performs inexpensive, high-recall triage, then sends suspicious sessions to a reasoning stage that can consult source code, policies, and threat intelligence.

The distinction between the public project and Uber’s complete internal system matters. Prevention is not included in the current open-source release, and the offline ADR Explorer shown in the paper is also excluded. What you can download is still substantial, but it is best understood as observability software plus a reproducible security research toolkit.

Official ADR Sensor observability pipeline across AI coding tools
Official Uber ADR MLSys 2026 slide showing how ADR Sensor reconstructs AI coding activity and forwards contextual telemetry for detection.

Main features

  • Cross-agent telemetry: Parsers normalize local session data from six named coding-agent environments into a shared AgentEvent schema.
  • Causal context: Events can preserve prompts, reasoning records, MCP calls, tool results, model details, and project context instead of recording only operating-system activity.
  • Flexible export: The Sensor CLI can scan all supported sources or one selected source, save incremental sessions, and export JSON or JSONL for downstream analysis.
  • ADR-Bench: The repository currently ships 303 scenarios, including 42 malicious tasks, plus 133 registered MCP servers spanning realistic, vulnerable, community, and official examples.
  • Two-tier detection: A lightweight triage stage aims to discard clearly benign sessions cheaply, while a reasoning agent examines ambiguous events with enterprise context.
  • Reproducible evaluation: A packed benchmark lets researchers skip live agent execution, run detectors against recorded conversations, and regenerate paper figures.

Product strengths and limitations

ADR’s strongest idea is that agent security needs intent and sequence, not just a list of file and network events. If an assistant was asked to summarize a ticket but instead opened SSH keys and made an HTTP request, the surrounding prompt, reasoning trace, and tool chain make the deviation much easier to investigate. The Sensor can also feed a team’s existing detection pipeline or SIEM rather than forcing a complete platform replacement.

The rough edges are equally important. Several supported log formats are private implementation details that may change as agent products update. The default ADR detector needs model credentials and a Claude CLI setup, so a full benchmark run is not free. Most importantly, the Detection documentation labels the benchmark as a research artifact, notes that reproducibility pins include dependencies with known CVEs, and requires an isolated container, VM, or dedicated host. Never connect its synthetic credentials or intentionally vulnerable MCP fixtures to live systems.

Official ADR two-tier detector and offline hardening architecture
Official Uber ADR MLSys 2026 slide showing high-recall triage, contextual reasoning, human investigation, and the offline red-team feedback loop.

How to install and use ADR

The simplest starting point is ADR Sensor. Use a fresh Python environment on a test machine, install the tagged package from PyPI, then scan one source before attempting a broad collection. The official CLI can write JSONL that you inspect locally or route into your own analysis workflow.

python -m venv .venv
pip install adr-sensor
adr-sensor --source codex --output-format jsonl

For ADR-Bench and the detector, clone the repository and work inside an isolated environment. The official setup uses uv sync. You can inflate the packed benchmark conversations without executing the vulnerable MCP scenarios, then run the LlamaFirewall baseline as a smaller keyless smoke test. The full ADR detector uses API keys and additional configuration described in the reproducibility guide.

git clone https://github.com/uber/ADR
cd ADR/Detection
uv sync
uv run python benchmark/benchmark_pack.py inflate benchmark/adr_bench_20251017_151604.jsonl --output-dir benchmark/adr_bench_20251017_151604
uv run python main_detector.py --detector llamafirewall --tasks 108 --results-dir benchmark/adr_bench_20251017_151604

Best use cases

Security teams can use ADR Sensor to explore what local coding agents actually did during an incident, then map normalized events into an existing investigation workflow. AI platform teams can evaluate whether a detector catches credential access, data exfiltration, malicious MCP behavior, or prompt-injection chains. Researchers can extend ADR-Bench with new tasks or compare detection approaches on the same recorded conversations.

ADR is a weaker fit for small teams looking for a polished dashboard, automatic blocking, or a managed service with support guarantees. It also should not be treated as a drop-in EDR replacement. A sensible pilot is to collect a narrow set of agent logs, verify exactly what sensitive content appears in the output, and only then decide how retention, access control, and alerting should work.

Pricing and license

ADR’s original code is available under the Apache License 2.0. The vendored AgentDojo benchmark directory has its own MIT license, and the repository notice documents additional fixture attributions. There is no subscription charge for the code, but full detector experiments may incur OpenAI or Anthropic API costs, along with compute, storage, and engineering time. Review the notices before redistributing a modified benchmark bundle.

My take

ADR is valuable because it releases concrete engineering artifacts around a problem that is often discussed only in broad security language. The Sensor is the easiest part to try, while the benchmark and detector are better suited to teams with security research experience. I especially like the split between cheap triage and selective deep reasoning; it reflects the uncomfortable reality that sending every benign session through an expensive model is not a workable production plan.

Go in with the right expectations. This is an early, advanced toolkit, not a finished enterprise console, and some of Uber’s hardening components remain private. For organizations already operating AI coding agents at scale, however, ADR offers a credible starting point for building visibility, testing defenses, and asking much sharper questions about agent behavior.