SAFE Agentic Framework

Open-source security standards for AI agents · Linux Foundation / OpenSSF

An OpenSSF / Linux Foundation Project·Led by Astha.ai

The open-source security standard for AI agents

Map, assess, and mitigate threats across the entire agentic AI attack surface.

AGENTIC THREAT FRAMEWORK

SAFE-MCP

14 Tactics85 Techniques

Security specification adapting MITRE ATT&CK for MCP environments.

Operates as a SIG under OpenSSF’s AI/ML Working Group, with project-level status in progress.

Explore SAFE-MCP
KUBERNETES & AI SECURITY CONTROLS

SAFE-K8S

593 Controls10 Domains55 Knowledge Areas

Security control catalog for Kubernetes clusters running AI workloads — from cluster hardening to GPU security, model serving, and RAG infrastructure.

4,916 crosswalk mappings to EU AI Act, NIST 800-53, NIST AI RMF, and NIST SSDF.

Explore SAFE-K8S
AGENTIC USE CASE ANALYSIS

SAFE-AUCA

33 Use Cases8 Industries

Community-driven library of real-world Agentic Use Case Analyses (AUCA) mapped to SAFE-MCP techniques.

Explore SAFE-AUCA

SAFE-MCP Threat Catalog

Adapts the MITRE ATT&CK methodology for MCP environments. Each technique includes actionable mitigations and maps to NIST SP 800-53, OWASP LLM Top 10, and the EU AI Act.

Severity
Attack Chain