ADR (Agentic AI Detection and Response) is Uber's open-source security system for enterprise AI agents, including employee-facing coding agents such as Cursor, Claude Code, Codex and GitHub Copilot CLI.
It discovers AI tools on endpoints, collects agent telemetry, and detects risky agent behavior, and is described in an MLSys 2026 paper.
- 01
ADR Discovery inventories AI apps, CLI agents, IDE extensions, local model runtimes and MCP servers on endpoints and flags unknown surfaces
- 02
ADR Sensor collects and normalizes session telemetry from Claude Code, Cursor, Codex, GitHub Copilot CLI, Gemini CLI, opencode, Claude Desktop and more
- 03
Cross-platform sensor for macOS, Linux and Windows
- 04
Two-tier detector combining high-recall triage with deeper agentic reasoning on suspicious sessions
- 05
ADR-Bench with 300+ tasks, 134 MCP servers and coverage of 17 agent attack techniques
- 06
Reproducibility guide for benchmark runs and paper figures
Open Source
ADR is released by Uber under the Apache-2.0 license and is free to self-host. Running the default ADR detector calls Anthropic and OpenAI models with your own API keys; a keyless LlamaFirewall baseline is available for smoke tests. The ADR Prevention component is not part of the open-source release.
Best for
Security and platform teams that need visibility into which AI coding agents and MCP servers employees run, and want to detect unsafe agent behavior across a fleet.
Not ideal for
Individual developers looking for a drop-in guardrail: ADR is an enterprise research-grade system, and its prevention (blocking) component is not included in the open-source release.
ADR is a credible, production-proven foundation for governing AI coding agents in an enterprise, backed by Uber's deployment and a peer-reviewed paper. It is strongest for discovery, observability and detection research; teams wanting enforcement will need to add their own prevention layer.
Open-sourced by Uber with the ADR Discovery, Sensor, ADR-Bench and Detector components; sensor-v1.0.0 was released in July 2026 and commits continued into October 2026, including Gemini CLI session capture.
As of
Is ADR free?+
Yes - ADR is Open Source. ADR is released by Uber under the Apache-2.0 license and is free to self-host. Running the default ADR detector calls Anthropic and OpenAI models with your own API keys; a keyless LlamaFirewall baseline is available for smoke tests. The ADR Prevention component is not part of the open-source release.
Is ADR open source?+
Yes - ADR is open source. ADR is released by Uber under the Apache-2.0 license and is free to self-host. Running the default ADR detector calls Anthropic and OpenAI models with your own API keys; a keyless LlamaFirewall baseline is available for smoke tests. The ADR Prevention component is not part of the open-source release.
Who is ADR best for?+
Security and platform teams that need visibility into which AI coding agents and MCP servers employees run, and want to detect unsafe agent behavior across a fleet.
Who is ADR not ideal for?+
Individual developers looking for a drop-in guardrail: ADR is an enterprise research-grade system, and its prevention (blocking) component is not included in the open-source release.
What are the best ADR alternatives?+
The closest ADR alternatives on ai.dosa.dev are CodeRabbit, Qodo, Snyk Code - all listed under AI Code Review & Security.
Who makes ADR?+
ADR is developed by Uber. It is listed in the AI Code Review & Security category on ai.dosa.dev.
Favorite this tool to revisit it later, or Zap it to contribute to the public vote count.