ATR Adopters
Every adoption below corresponds to a merged GitHub PR with an external reviewer. Drafts, in-flight PRs, and self-published artifacts are not listed here.
Production merges: Microsoft AGT (PR #908 + #1277) + Cisco AI Defense (PR #79 + #99) + MISP taxonomies #323 + MISP galaxy #1207 + OWASP A-S-R-H #74 + Gen Digital Sage #33 — 7 PRs across 6 ecosystems. Plus 4 awesome-list inclusions (not counted as production adoption).
Production Adoption
Reviewed and merged by external maintainers
Microsoft Agent Governance Toolkit
287-rule expansion in production with weekly auto-sync workflow. Microsoft Copilot SWE Agent opened AGT#1981 with regression-test fixtures presuming ATR detection (2026-05-11).
Cisco AI Defense
Full 419-rule pack in skill-scanner production. Auto-syncs to latest ATR release.
MISP (CIRCL)
336-rule cluster in global threat-intel sharing (galaxy). Rule-ID tagging vocabulary in taxonomies. CIRCL is Luxembourg national CERT.
OWASP Agent Security Regression Harness
Project Lead Mert Satilmaz merged with "Welcome to the team" greeting.
Gen Digital Sage
Norton / Avast / AVG parent (consumer security). Merged by Václav Belák.
Listed in Awesome Lists
Listing is not production adoption, but reflects community visibility
Open PRs (Not Yet Merged)
Reflects in-flight conversations, not adoption
| Org / Project | Status |
|---|---|
| NIST AI RMF (OSCAL) | Path 1 accepted 2026-05-11 |
| NVIDIA garak | PR #1676 open |
| IBM mcp-context-forge | PR #4109 open |
| OWASP LLM Top 10 | Issue #814 open |
| safe-agentic-framework/safe-mcp | PR #187 open |
| meta-llama/PurpleLlama | PR #206 open |
| promptfoo/promptfoo | PR #8529 open |
Want to become an adopter?
All rules are MIT-licensed; no agreement needed to use. After production deployment, open an issue to be added — this page syncs on each release.