AVE Project: Creating a Shared Vocabulary for AI Agent Vulnerabilities

SelectionBitter6821 · reddit · 2026-08-26

The author introduces AVE (Agentic Vulnerability Enumeration), a project designed to create a unified naming and classification standard for AI Agent vulnerabilities, similar to CVE/CWE in traditional software. Current AI governance frameworks focus on risk categories (e.g., excessive agency, tool misuse) but lack the ability to track specific behavioral patterns. AVE provides 80 stable IDs for distinct behavioral vulnerabilities in skill files, MCP servers, and agent plugins, mapped to standards like OWASP and MITRE ATLAS. Three independent security tools have converged on the same AVE IDs, validating the standard's practical utility.

Original post →

More from coding & agent

coding & agent channel →