Tech Meridian ← LIVE FEED
PROMY MERIDIAN RU

RESEARCH · RESEARCH · #1482

Archestra releases OpenAPPA; reports 0% attack success on two agent-security benchmarks

Archestra published OpenAPPA, an open-source security engine and policy framework (Agentic Permissions Policy Algebra, APPA) that runs outside an agent’s prompt/execution loop and enforces deterministic, lattice-based data-audience/trust rules. In reported runs on Bench-Corp and AgentThreatBench (also referred to as OWASP AgentThreatBench), the team states OpenAPPA had a 0% attack success rate with an 89% task completion rate versus 10% (≈90% completion) for Claude Code’s auto mode and 31% (≈41% completion) for Microsoft FIDES.

KEY POINTS

  1. Archestra published OpenAPPA, an open-source security engine and policy framework (Agentic Permissions Policy Algebra, APPA) that runs outside an agent’s prompt/execution loop and enforces deterministic, lattice-based data-audience/trust rules.
  2. In reported runs on Bench-Corp and AgentThreatBench (also referred to as OWASP AgentThreatBench), the team states OpenAPPA had a 0% attack success rate with an 89% task completion rate versus 10% (≈90% completion) for Claude Code’s auto mode and 31% (≈41% completion) for Microsoft FIDES.
  3. If reproducible, an out-of-loop, deterministic policy engine that blocks agent data-exfiltration while preserving high task completion could materially change how organizations secure autonomous agent workflows.

WHY IT MATTERS

If reproducible, an out-of-loop, deterministic policy engine that blocks agent data-exfiltration while preserving high task completion could materially change how organizations secure autonomous agent workflows.

SOURCES & TIMELINE

1