# ADR (Agentic AI Detection and Response)

> Updated 2026-10-07 · type: tool · category: mcp-agents · status: active · rev 1

ADR is Uber's Apache-2.0 platform that inventories, monitors, and detects threats across the AI agents and MCP servers running on your endpoints.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing model: free
- Best for: A technical team that has put AI coding or ops agents (Claude Code, Cursor, Codex, Copilot CLI) onto machines that touch sensitive systems and wants to inventory what agents and MCP servers are running, collect their telemetry, and detect suspicious sessions, on infrastructure it owns.
- Not for: A lean GTM team with no deployed agents to secure yet, a non-technical operator wanting a managed SaaS with support, or anyone needing GTM-specific controls (this is general enterprise-agent security, not CRM-field or go-to-market-specific governance).
- Last verified: 2026-10-08

- **Canonical:** https://gtmstacker.com/registry/tool/uber-adr/
- **Source:** [uber/adr · X (@RoundtableSpace) / GitHub](https://github.com/uber/adr)
- **Tags:** mcp-agents, ai-infrastructure, agent-security, governance, observability, self-hostable, open-source
- **Repository:** https://github.com/uber/adr

## Is ADR (Agentic AI Detection and Response) open source?

Yes, ADR (Agentic AI Detection and Response) is open source under the Apache-2.0 license.

## How much does ADR (Agentic AI Detection and Response) cost?

ADR (Agentic AI Detection and Response) is free to use.

## Can I self-host ADR (Agentic AI Detection and Response)?

Yes, ADR (Agentic AI Detection and Response) can be self-hosted (the source is available under the Apache-2.0 license).


---

ADR, short for Agentic AI Detection and Response, is Uber's open-source platform for securing the AI agents a team actually runs. As operators put coding and ops agents onto machines that reach real systems, ADR answers three questions: what agents and MCP servers are running, what are they doing, and which sessions look dangerous. Open source: yes (Apache-2.0); self-hostable; free. It is in production at Uber and was accepted to MLSys 2026.

## What it does

ADR has three parts. Discovery inventories the AI apps, CLI agents, IDE extensions, model runtimes, and MCP servers present on an endpoint, so you know what is installed before you reason about risk. The Sensor collects and normalizes agent telemetry from Claude Code, Cursor, Codex, GitHub Copilot CLI, and DeepSeek Harness across macOS, Linux, and Windows. The Detection layer is a dual-agent detector that pairs high-recall triage with deeper agentic reasoning on the sessions that look suspicious. It ships with ADR-Bench, a benchmark of more than 300 tasks spanning 134 MCP servers and all 17 agent attack techniques, so detection quality can be measured rather than asserted.

## Provenance

- Apache-2.0 per repo (license and metadata read from the GitHub API, not guessed); uber/adr; created 2026-04-19; pushed 2026-10-07; not archived; ~1871 stars; Python; latest release sensor-v1.0.0 (2026-07-31); verified 2026-10-08.
- README (maker-stated, read 2026-10-08): Discovery, Sensor, and dual-agent Detection components; supported agents Claude Code, Cursor, Codex, GitHub Copilot CLI, DeepSeek Harness; ADR-Bench with 300+ tasks, 134 MCP servers, and 17 agent attack techniques; in production at Uber; accepted to MLSys 2026.
- Surfaced in the GTM Stacker signal run (2026-10-08 pass) via an X post and the X-OSS lane; license and repo facts re-verified against the GitHub repo and README 2026-10-08.

## Why it matters for a GTM stack

The owned, agent-native GTM stack this registry tracks has a governance edge: once an agent can read your CRM, write to your pipeline, or run outreach, the question is not only what it can do but what it is actually doing and when something is wrong. ADR is the detection-and-response side of that story. It is honestly general enterprise-agent security rather than a GTM-specific control, and it earns a place here the same way agent data-access and attack-surface tools do, because the agents it watches are increasingly the ones running on your go-to-market data. For a technical team already putting Claude Code or Cursor near revenue systems, ADR is a license-clean, self-hostable way to inventory those agents, collect their telemetry, and measure detection against a public benchmark, on infrastructure it owns.
