# AURA: AI User Risk Assessment Framework

> An open-source library of structured behavioral matrices, heuristics, and validation tooling to detect manipulation, deception, and grey-zone threats in human–AI interactions.

AURA (AI User Risk Assessment) is an open-source TypeScript library created by Ecaterina Sevciuc and published on GitHub under the Apache License 2.0. It provides structured behavioral matrices, heuristic risk scoring, and AJV-backed JSON schema validation tooling designed to help developers detect social engineering, manipulation, and deception in LLM interactions. The project released its first versioned release, v0.1.0, in September 2026.

## What It Is

AURA is a behavioral threat-intelligence framework for AI safety. Rather than relying on static safety guardrails, it focuses on the psychological and tactical vectors of social engineering — covering privilege escalation, financial fraud bypass, compliance evasion, gaslighting, and psychological pressure. Each threat case is stored as a self-contained JSON file validated against a strict schema, making the library easy to parse, update, and integrate into CI/CD pipelines or AI training workflows.

The framework organizes cases into three core domains:
- **MANIPULATION** — social engineering, gaslighting, and psychological pressure
- **FRAUD** — financial bypass, compliance evasion, and social fraud
- **ACCESS** — privilege escalation, unauthorized OSINT, and credential probing

## How the Threat Scoring Works

AURA uses a dynamic heuristic confidence scoring system. Triggers are counted per case, with the most frequent trigger mapped to a top weight and others scaled linearly relative to that maximum. Final confidence for a case is computed as a base score (by category) plus a boost derived from trigger weights, cross-check questions, and unmapped signal IDs. The normalized `confidence` field (range 0–1) is computed from a raw evidence sum (`confidence_raw`) using a diminishing-returns transform, keeping the auditable raw value separate for reviewability.

Signal IDs use a namespaced compact key format (e.g., `camouflage:naive`, `recon:targeted`), and the canonical mapping lives in `config/signal-mapping.json`. Scripts like `npm run gen:triggers` and `npm run recalc:confidence` automate weight generation and confidence recalculation, and can be wired into GitHub Actions for continuous updates.

## Developer Tooling and Architecture

The repository is structured for developer ergonomics:
- **`public_cases/`** — curated open-source threat library organized by domain
- **`schemas/`** — JSON schemas for validating every case
- **`scripts/`** — validation, normalization, confidence recalculation, cross-check, and audit utilities
- **`config/`** — runtime mappings and generated configs (`signal-mapping.json`, `trigger-weights.json`)

Key npm scripts include `validate`, `normalize:percases`, `new-case`, `gen:triggers`, `recalc:confidence`, `collect:triggers`, `audit:categories`, and `crosscheck:run`. The toolchain requires Node.js 18 or later and uses Jest for automated testing.

## Roadmap and Collaboration Model

The project is maintainer-led with a published governance model. The roadmap highlights three active research directions:
1. **Programmatic prompt tokenization** — a TypeScript engine to dynamically generate thousands of test cases from structural templates (Persona + Target + Evasion Method + Alibi)
2. **Algorithmic cross-checking** — automated verification of user-claimed personas against expected documentation signals
3. **Multilingual security testing** — expanding threat matrices to cover idiomatic nuances in non-English languages, starting with Russian

The `public_cases/` dataset is available under CC BY-NC 4.0 for non-commercial evaluation, benchmarking, and research. Commercial licensing, private dataset exports, and enterprise API access are available upon request.

## Update: v0.1.0 Release

The first versioned release, v0.1.0, was published on September 26, 2026. The repository was created in July 2026 and has been actively developed since, with the last push recorded on the same date as the release. Recent changes include compacting signal IDs to a namespaced key format and adding one-off migration scripts (`migrate:categories`, `migrate:signals`) exposed as npm commands. The project has been covered on Dev.to and CoderLegion as a behavioral threat-intelligence framework for AI safety.

## Features
- Granular threat categorization across MANIPULATION, FRAUD, and ACCESS domains
- Heuristic risk scoring with dynamic confidence recalculation
- AJV-backed JSON schema validation for all behavioral cases
- Self-contained JSON case files for easy CI/CD integration
- Signal ID namespaced key format with canonical mapping
- npm scripts for validation, normalization, confidence recalculation, and auditing
- Cross-check adapter module for automated verification
- Case generator with dry-run support
- GitHub Actions-compatible automation for trigger weight generation
- CC BY-NC 4.0 licensed public dataset for non-commercial research

## Integrations
Node.js, npm, yarn, AJV (JSON schema validation), Jest, GitHub Actions, TypeScript, CI/CD pipelines

## Platforms
CLI, API, DEVELOPER_SDK

## Pricing
Open Source, Free tier available

## Version
v0.1.0

## Links
- Website: https://github.com/kate8382/AURA
- Documentation: https://github.com/kate8382/AURA/blob/main/docs/SCRIPTS.md
- Repository: https://github.com/kate8382/AURA
- EveryDev.ai: https://www.everydev.ai/tools/aura-ai-user-risk-assessment
