Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

README.md

AVE, Agentic Vulnerability Enumeration

An open, vendor-neutral behavioral classification standard for agentic AI components.

Skill files, MCP servers, system prompts, and agent plugins are executable instructions, not documentation. AVE assigns stable IDs to the distinct behavioral vulnerability classes that emerge when an LLM reads and acts on that kind of content, scored with OWASP's AIVSS framework, crosswalked into OWASP MCP Top 10, MITRE ATLAS, and NIST AI RMF.

Website · API · Registry · GitHub · Contact


What's here

ave: the standard itself — records, schema, crosswalks, and the governance and contribution process.

ave-api: read-only reference API for AVE. Not the standard itself, see ave.

ave-site: the public website and API source.

Independent validation

AVE's ID scheme has been tested by people who didn't build it. 80 records, crosswalked against 8 independent tools that share no code with AVE or with each other — cfgaudit, ClawScan, nova-proximity, Ramparts, Semia, SkillSpector (NVIDIA), skill-security-scanner, and skillsentry — checked at the mechanism level, not by matching category labels.

License

Apache 2.0, records and code both.