EveryDev.ai
Subscribe
Home
Tools

4,072+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2782
  • Coding1973
  • Infrastructure825
  • Projects603
  • Marketing598
  • Research520
  • Analytics468
  • Design462
  • MCP419
  • Testing346
  • Security323
  • Data305
  • Integration224
  • Prompts220
  • Communication210
  • Extensions196
  • Learning179
  • Voice175
  • Commerce160
  • DevOps135
  • Web95
  • Finance31
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. AURA: AI User Risk Assessment Framework
    AURA: AI User Risk Assessment Framework icon

    AURA: AI User Risk Assessment Framework

    Application Security

    An open-source library of structured behavioral matrices, heuristics, and validation tooling to detect manipulation, deception, and grey-zone threats in human–AI interactions.

    Visit Website

    At a Glance

    Pricing
    Open Source
    Free tier available

    Fully open-source under Apache License 2.0 (code) and CC BY-NC 4.0 (public dataset). Free for non-commercial use, evaluation, benchmarking, and research.

    Commercial License: Custom/contact

    Engagement

    Available On

    CLI
    API
    SDK

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Application SecurityAI Development LibrariesThreat Detection

    Alternatives

    PromptArmorUnit 42 Frontier AI DefenseZeron
    Developer
    Ecaterina SevciucEcaterina Sevciuc builds open-source AI safety tooling focus…

    Listed Sep 2026

    About AURA: AI User Risk Assessment Framework

    AURA (AI User Risk Assessment) is an open-source TypeScript library created by Ecaterina Sevciuc and published on GitHub under the Apache License 2.0. It provides structured behavioral matrices, heuristic risk scoring, and AJV-backed JSON schema validation tooling designed to help developers detect social engineering, manipulation, and deception in LLM interactions. The project released its first versioned release, v0.1.0, in September 2026.

    What It Is

    AURA is a behavioral threat-intelligence framework for AI safety. Rather than relying on static safety guardrails, it focuses on the psychological and tactical vectors of social engineering — covering privilege escalation, financial fraud bypass, compliance evasion, gaslighting, and psychological pressure. Each threat case is stored as a self-contained JSON file validated against a strict schema, making the library easy to parse, update, and integrate into CI/CD pipelines or AI training workflows.

    The framework organizes cases into three core domains:

    • MANIPULATION — social engineering, gaslighting, and psychological pressure
    • FRAUD — financial bypass, compliance evasion, and social fraud
    • ACCESS — privilege escalation, unauthorized OSINT, and credential probing

    How the Threat Scoring Works

    AURA uses a dynamic heuristic confidence scoring system. Triggers are counted per case, with the most frequent trigger mapped to a top weight and others scaled linearly relative to that maximum. Final confidence for a case is computed as a base score (by category) plus a boost derived from trigger weights, cross-check questions, and unmapped signal IDs. The normalized confidence field (range 0–1) is computed from a raw evidence sum (confidence_raw) using a diminishing-returns transform, keeping the auditable raw value separate for reviewability.

    Signal IDs use a namespaced compact key format (e.g., camouflage:naive, recon:targeted), and the canonical mapping lives in config/signal-mapping.json. Scripts like npm run gen:triggers and npm run recalc:confidence automate weight generation and confidence recalculation, and can be wired into GitHub Actions for continuous updates.

    Developer Tooling and Architecture

    The repository is structured for developer ergonomics:

    • public_cases/ — curated open-source threat library organized by domain
    • schemas/ — JSON schemas for validating every case
    • scripts/ — validation, normalization, confidence recalculation, cross-check, and audit utilities
    • config/ — runtime mappings and generated configs (signal-mapping.json, trigger-weights.json)

    Key npm scripts include validate, normalize:percases, new-case, gen:triggers, recalc:confidence, collect:triggers, audit:categories, and crosscheck:run. The toolchain requires Node.js 18 or later and uses Jest for automated testing.

    Roadmap and Collaboration Model

    The project is maintainer-led with a published governance model. The roadmap highlights three active research directions:

    1. Programmatic prompt tokenization — a TypeScript engine to dynamically generate thousands of test cases from structural templates (Persona + Target + Evasion Method + Alibi)
    2. Algorithmic cross-checking — automated verification of user-claimed personas against expected documentation signals
    3. Multilingual security testing — expanding threat matrices to cover idiomatic nuances in non-English languages, starting with Russian

    The public_cases/ dataset is available under CC BY-NC 4.0 for non-commercial evaluation, benchmarking, and research. Commercial licensing, private dataset exports, and enterprise API access are available upon request.

    Update: v0.1.0 Release

    The first versioned release, v0.1.0, was published on September 26, 2026. The repository was created in July 2026 and has been actively developed since, with the last push recorded on the same date as the release. Recent changes include compacting signal IDs to a namespaced key format and adding one-off migration scripts (migrate:categories, migrate:signals) exposed as npm commands. The project has been covered on Dev.to and CoderLegion as a behavioral threat-intelligence framework for AI safety.

    AURA: AI User Risk Assessment Framework - 1

    Community Discussions

    Be the first to start a conversation about AURA: AI User Risk Assessment Framework

    Share your experience with AURA: AI User Risk Assessment Framework, ask questions, or help others learn from your insights.

    Pricing

    OPEN SOURCE

    Open Source

    Fully open-source under Apache License 2.0 (code) and CC BY-NC 4.0 (public dataset). Free for non-commercial use, evaluation, benchmarking, and research.

    • Full access to public_cases/ threat library
    • JSON schema validation tooling
    • Heuristic confidence scoring scripts
    • Case generator and normalization utilities
    • CI/CD integration support

    Commercial License

    Commercial licensing, private dataset exports, NDA, and private API access available upon request for enterprise and commercial use cases.

    Custom
    contact sales
    • Commercial license for public_cases/ dataset
    • Private dataset exports
    • NDA support
    • Private API access
    • Sandboxed evaluation pipeline for private cases
    View official pricing

    Capabilities

    Key Features

    • Granular threat categorization across MANIPULATION, FRAUD, and ACCESS domains
    • Heuristic risk scoring with dynamic confidence recalculation
    • AJV-backed JSON schema validation for all behavioral cases
    • Self-contained JSON case files for easy CI/CD integration
    • Signal ID namespaced key format with canonical mapping
    • npm scripts for validation, normalization, confidence recalculation, and auditing
    • Cross-check adapter module for automated verification
    • Case generator with dry-run support
    • GitHub Actions-compatible automation for trigger weight generation
    • CC BY-NC 4.0 licensed public dataset for non-commercial research

    Integrations

    Node.js
    npm
    yarn
    AJV (JSON schema validation)
    Jest
    GitHub Actions
    TypeScript
    CI/CD pipelines
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate AURA: AI User Risk Assessment Framework and help others make informed decisions.

    Developer

    Ecaterina Sevciuc

    Ecaterina Sevciuc builds open-source AI safety tooling focused on behavioral threat intelligence for LLM interactions. She created AURA, a framework of structured behavioral matrices and validation tooling designed to detect manipulation, deception, and social engineering in human–AI systems. Her work addresses gaps in multilingual AI alignment and psychological attack vectors that static guardrails miss.

    Read more about Ecaterina Sevciuc
    WebsiteGitHubLinkedIn
    1 tool in directory

    Similar Tools

    PromptArmor icon

    PromptArmor

    PromptArmor is a comprehensive AI risk platform that helps enterprise security teams identify, assess, monitor, and map AI risks across third-party vendors and internal systems.

    Unit 42 Frontier AI Defense icon

    Unit 42 Frontier AI Defense

    Unit 42 Frontier AI Defense is a threat intelligence and security consulting service from Palo Alto Networks that helps organizations assess and defend against risks introduced by frontier AI models.

    Zeron icon

    Zeron

    AI-powered cyber risk management platform that quantifies risks, automates compliance, and provides real-time threat intelligence for enterprises.

    Browse all tools

    Related Topics

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    126 tools

    AI Development Libraries

    Programming libraries and frameworks that provide machine learning capabilities, model integration, and AI functionality for developers.

    328 tools

    Threat Detection

    AI tools that detect and analyze security threats and anomalies.

    35 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions