NVIDIA-NeMo / NVIDIA-NeMo/Guardrails

Proposal: Load Agent Threat Rules (ATR) detection patterns as Colang rails

Open
#1,872 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
7.2k
Forks
843
Avg merge
3d 1h
Merged PRs (30d)
25

Description

Proposal — Load Agent Threat Rules (ATR) detection patterns as Colang rails

Hi NeMo-Guardrails team,

I maintain Agent Threat Rules (ATR), an open detection standard for AI agent attacks (Apache 2.0, https://github.com/Agent-Threat-Rule/agent-threat-rules). Filing this as a proposal because the integration is a clean fit with how NeMo-Guardrails composes rails today and I want to know if you'd accept the PR before I open it.

What ATR is
  • 338 YAML detection rules across 10 attack categories: prompt-injection, tool-poisoning, context-exfiltration, excessive-autonomy, privilege-escalation, agent-manipulation, data-poisoning, model-abuse, skill-compromise, model-security
  • 97.1% recall on NVIDIA garak (independent benchmark)
  • 100% recall / 97% precision / 0.20% FP on 498 real-world SKILL.md samples
  • Already in production: Cisco AI Defense (skill-scanner #79, merged), Microsoft (agent-governance-toolkit #908, merged), OWASP Agentic Top 10 (precize repo #14, merged), MISP taxonomy + galaxy (#323 + #1207, submitted 2026-05-10)
  • 96,096 skills wild-scanned, 751 confirmed malware skills found in production ecosystems
Why NeMo-Guardrails specifically

You already model rails as composable Colang flows. ATR provides a curated, severity-tagged, MITRE ATLAS / OWASP Agentic-Top-10 / SAFE-MCP cross-walked catalog of detection patterns. Loading ATR rules as a Colang library would:

  1. Cut the time from new threat disclosure to deployable rail. Example: Microsoft Semantic Kernel CVE-2026-26030 (lambda+eval RCE) had ATR rules merged within 4 days of MSRC disclosure (5/7 → 5/11), shipped as @agent-threat-rules v2.1.2 on npm. NeMo users on nemoguardrails[atr] would inherit those rails on next install.
  2. Cover MCP-specific surfaces (tool poisoning, skill compromise, excessive autonomy) that don't have first-party rails today.
  3. Map cleanly to OWASP Agentic-Top-10 categories — useful when users ask "which rails cover LLM06 sensitive info disclosure?"
Proposed integration shape

Option A — optional extra: pip install nemoguardrails[atr] pulls our Python loader that compiles each ATR YAML into a Colang define flow block. Configurable per category/severity.

Option B — example library: ship as examples/atr_rails/ reference with a tutorial. Lower lift, also lower discoverability.

I lean toward A, but happy to start with B if that matches your roadmap better.

What I'd contribute
  • Loader (Python, MIT) that maps condition / agent_source / response from the ATR schema to Colang flows
  • 10 example flows (one per category) shipped in the repo
  • CI test against the existing benchmark in nvidia/aegis-ai-content-safety-test so a NeMo PR can prove FP rate stays under their thresholds
  • Maintenance: ATR ships patch releases when wild-scans find new patterns (last 30 days: 26 → 338 rules). Cisco's pinned the rules in their own ATR mirror and I'd do the same for NeMo so version pin is the user's choice.
What I need from you
  • Yes / no on the integration angle
  • Pointer to the right Colang flow primitive if option A's loader output should look different from what I'd guess from the docs

Not asking for prioritization or maintainer time beyond review. If this isn't a fit, "not now" is a fine answer — I'll close.

Refs:

Thanks for the time. Will hold off on opening a PR until I hear back.

— Adam Lin (linkedin/eeee2345)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the proposed Python loader boundary, the ATR YAML schema, and the existing Colang flow primitives. Decide whether an optional package extra or an examples/atr_rails library fits the project, then define the loader and benchmark scope before implementation; done requires maintainer agreement on the integration shape.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
ai, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.