AURA: AI User Risk Assessment Framework
An open-source library of structured behavioral matrices, heuristics, and validation tooling to detect manipulation, deception, and grey-zone threats in human–AI interactions.
At a Glance
Fully open-source under Apache License 2.0 (code) and CC BY-NC 4.0 (public dataset). Free for non-commercial use, evaluation, benchmarking, and research.
Engagement
Available On
Alternatives
Listed Sep 2026
About AURA: AI User Risk Assessment Framework
AURA (AI User Risk Assessment) is an open-source TypeScript library created by Ecaterina Sevciuc and published on GitHub under the Apache License 2.0. It provides structured behavioral matrices, heuristic risk scoring, and AJV-backed JSON schema validation tooling designed to help developers detect social engineering, manipulation, and deception in LLM interactions. The project released its first versioned release, v0.1.0, in September 2026.
What It Is
AURA is a behavioral threat-intelligence framework for AI safety. Rather than relying on static safety guardrails, it focuses on the psychological and tactical vectors of social engineering — covering privilege escalation, financial fraud bypass, compliance evasion, gaslighting, and psychological pressure. Each threat case is stored as a self-contained JSON file validated against a strict schema, making the library easy to parse, update, and integrate into CI/CD pipelines or AI training workflows.
The framework organizes cases into three core domains:
- MANIPULATION — social engineering, gaslighting, and psychological pressure
- FRAUD — financial bypass, compliance evasion, and social fraud
- ACCESS — privilege escalation, unauthorized OSINT, and credential probing
How the Threat Scoring Works
AURA uses a dynamic heuristic confidence scoring system. Triggers are counted per case, with the most frequent trigger mapped to a top weight and others scaled linearly relative to that maximum. Final confidence for a case is computed as a base score (by category) plus a boost derived from trigger weights, cross-check questions, and unmapped signal IDs. The normalized confidence field (range 0–1) is computed from a raw evidence sum (confidence_raw) using a diminishing-returns transform, keeping the auditable raw value separate for reviewability.
Signal IDs use a namespaced compact key format (e.g., camouflage:naive, recon:targeted), and the canonical mapping lives in config/signal-mapping.json. Scripts like npm run gen:triggers and npm run recalc:confidence automate weight generation and confidence recalculation, and can be wired into GitHub Actions for continuous updates.
Developer Tooling and Architecture
The repository is structured for developer ergonomics:
public_cases/— curated open-source threat library organized by domainschemas/— JSON schemas for validating every casescripts/— validation, normalization, confidence recalculation, cross-check, and audit utilitiesconfig/— runtime mappings and generated configs (signal-mapping.json,trigger-weights.json)
Key npm scripts include validate, normalize:percases, new-case, gen:triggers, recalc:confidence, collect:triggers, audit:categories, and crosscheck:run. The toolchain requires Node.js 18 or later and uses Jest for automated testing.
Roadmap and Collaboration Model
The project is maintainer-led with a published governance model. The roadmap highlights three active research directions:
- Programmatic prompt tokenization — a TypeScript engine to dynamically generate thousands of test cases from structural templates (Persona + Target + Evasion Method + Alibi)
- Algorithmic cross-checking — automated verification of user-claimed personas against expected documentation signals
- Multilingual security testing — expanding threat matrices to cover idiomatic nuances in non-English languages, starting with Russian
The public_cases/ dataset is available under CC BY-NC 4.0 for non-commercial evaluation, benchmarking, and research. Commercial licensing, private dataset exports, and enterprise API access are available upon request.
Update: v0.1.0 Release
The first versioned release, v0.1.0, was published on September 26, 2026. The repository was created in July 2026 and has been actively developed since, with the last push recorded on the same date as the release. Recent changes include compacting signal IDs to a namespaced key format and adding one-off migration scripts (migrate:categories, migrate:signals) exposed as npm commands. The project has been covered on Dev.to and CoderLegion as a behavioral threat-intelligence framework for AI safety.
Community Discussions
Be the first to start a conversation about AURA: AI User Risk Assessment Framework
Share your experience with AURA: AI User Risk Assessment Framework, ask questions, or help others learn from your insights.
Pricing
Open Source
Fully open-source under Apache License 2.0 (code) and CC BY-NC 4.0 (public dataset). Free for non-commercial use, evaluation, benchmarking, and research.
- Full access to public_cases/ threat library
- JSON schema validation tooling
- Heuristic confidence scoring scripts
- Case generator and normalization utilities
- CI/CD integration support
Commercial License
Commercial licensing, private dataset exports, NDA, and private API access available upon request for enterprise and commercial use cases.
- Commercial license for public_cases/ dataset
- Private dataset exports
- NDA support
- Private API access
- Sandboxed evaluation pipeline for private cases
Capabilities
Key Features
- Granular threat categorization across MANIPULATION, FRAUD, and ACCESS domains
- Heuristic risk scoring with dynamic confidence recalculation
- AJV-backed JSON schema validation for all behavioral cases
- Self-contained JSON case files for easy CI/CD integration
- Signal ID namespaced key format with canonical mapping
- npm scripts for validation, normalization, confidence recalculation, and auditing
- Cross-check adapter module for automated verification
- Case generator with dry-run support
- GitHub Actions-compatible automation for trigger weight generation
- CC BY-NC 4.0 licensed public dataset for non-commercial research
