Skip to content

ATR detection rules integration — 108 rules complementing SecureClaw's 15 behavioral rules #8

@eeee2345

Description

@eeee2345

SecureClaw has 51 audit checks + 15 behavioral rules for OpenClaw agents. ATR (Agent Threat Rules) maintains 108 regex detection rules covering a different layer — MCP tool poisoning, SKILL.md supply chain attacks, credential exfiltration, and prompt injection patterns.

They complement each other: SecureClaw does runtime hardening + behavioral rules, ATR does pattern-based threat detection.

Cisco AI Defense ships 34 ATR rules in production. 53K+ skills scanned, 0% FP on clean content.

Would you be open to a PR that integrates ATR detection patterns alongside SecureClaw's existing rules? Happy to match your format.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions