SECURITY · FRAMEWORK COVERAGE

Controls mapped to selected framework risks.

Security reviews are organised by OWASP, MITRE ATLAS and NIST identifiers. This page lists which of those items ClawMetry's Guard findings are relevant to, what each finding can and cannot establish, and every item nothing is mapped to. It describes coverage, not compliance: a mapping means a finding can draw a reviewer's attention to related activity. It does not mean the risk is prevented, and no certification or conformance follows from it.

How to read the tables

Every Guard finding is raised after the activity it describes, never before a tool runs. For every finding: observe yes, detect yes, evidence yes, pre-action control no. A Guard policy may pause, stop or kill a session after a finding. That is configured per node and is not counted as coverage here. The pre-tool gates, which can hold an action before it runs, are not yet part of this mapping.

DetectA finding is raised on the daemon's next pass over the session, after the call it describes.
EvidenceThe finding is kept with its framework identifiers and the mapping version, so a reviewer can inspect it later.
GapNo Guard finding is mapped to the item. Guard does not claim coverage of it.
Policy decisionsEach carries an evidence level: configured (a policy matched and no action ran), exercised (a pause, stop or kill ran and reported success) or failed. effective is never assigned, because nothing independently observes the outcome yet.

Mapping version and editions

Mapping version 2026-09-14.1, mirrored from the OSS framework coverage document at commit b53ff6c63e, which the product generates from its mapping contract (clawmetry/framework_map.py). CI in the product fails when that document and the contract disagree.

Framework editions the identifiers were verified against
FrameworkEditionSourceRevision
OWASP Top 10 for LLM Applications2026 v1.0https://genai.owasp.org/ (OWASP-GenAI-LLM-Top-10-2026-v1.0.pdf)v1.0 document, title page dated 2026-08-04
OWASP Top 10 for Agentic Applications2026https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/Version 2026 document, December 2025
MITRE ATLAS2026.08https://github.com/mitre-atlas/atlas-data/blob/main/dist/v6/ATLAS-2026.08.yamlgit blob dfd4e180fdca949eb26cb59555d9c346adcd6781, format-version 6.0.0; the identifiers below carry the same type and name in 2026.06, the edition OWASP LLM 2026 v1.0 cites

OWASP Top 10 for LLM Applications 2026

OWASP Top 10 for LLM Applications 2026: each item, the Guard findings mapped to it, and what that coverage is
IdentifierGuard findingsCoverageNeeds
LLM01:2026 Prompt InjectionNoneGap No Guard finding is mapped to this item.Not applicable
LLM02:2026 Sensitive Information Disclosurecredential_accessDetect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
LLM03:2026 Excessive Agencyfile_blast_radius
privilege_change
Detect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
LLM04:2026 Supply ChainNoneGap No Guard finding is mapped to this item.Not applicable
LLM05:2026 Data and Model PoisoningNoneGap No Guard finding is mapped to this item.Not applicable
LLM06:2026 Unbounded Consumptionstuck_loop
no_progress
Detect Evidence After the activity, not before it.a runtime whose adapter records tool calls
LLM07:2026 Misinformationaction_discrepancyDetect Evidence After the activity, not before it.a runtime whose adapter records tool results
LLM08:2026 Hidden Context ExposureNoneGap No Guard finding is mapped to this item.Not applicable
LLM09:2026 Vector and Embedding WeaknessesNoneGap No Guard finding is mapped to this item.Not applicable
LLM10:2026 Improper Output HandlingNoneGap No Guard finding is mapped to this item.Not applicable

OWASP Top 10 for Agentic Applications 2026

OWASP Top 10 for Agentic Applications 2026: each item, the Guard findings mapped to it, and what that coverage is
IdentifierGuard findingsCoverageNeeds
ASI01 Agent Goal HijackNoneGap No Guard finding is mapped to this item.Not applicable
ASI02 Tool Misuse and Exploitationstuck_loop
no_progress
file_blast_radius
network_egress
Detect Evidence After the activity, not before it.a runtime whose adapter records tool calls
a runtime whose adapter records tool-call arguments
a runtime whose adapter records tool-call arguments; a cohort baseline for first-time hosts
ASI03 Identity and Privilege Abusecredential_access
privilege_change
Detect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
ASI04 Agentic Supply Chain Vulnerabilitiesagent_config_tamper
package_manifest_exec
Detect Evidence After the activity, not before it.the session's working directory is known
ASI05 Unexpected Code Execution (RCE)repo_config_exec
package_manifest_exec
Detect Evidence After the activity, not before it.the session's working directory is known
ASI06 Memory & Context PoisoningNoneGap No Guard finding is mapped to this item.Not applicable
ASI07 Insecure Inter-Agent Communicationcoordinated_actionDetect Evidence After the activity, not before it.several unrelated session families and a full settle window of node memory
ASI08 Cascading Failurescoordinated_actionDetect Evidence After the activity, not before it.several unrelated session families and a full settle window of node memory
ASI09 Human-Agent Trust ExploitationNoneGap No Guard finding is mapped to this item.Not applicable
ASI10 Rogue AgentsNoneGap No Guard finding is mapped to this item.Not applicable

MITRE ATLAS

Not enumerated in full. ATLAS catalogs hundreds of adversary techniques; only the identifiers in the table below are claimed.

MITRE ATLAS: each item, the Guard findings mapped to it, and what that coverage is
IdentifierGuard findingsCoverageNeeds
AML.T0034.002 Agentic Resource Consumption (technique)stuck_loop
no_progress
Detect Evidence After the activity, not before it.a runtime whose adapter records tool calls
AML.T0101 Data Destruction via AI Agent Tool Invocation (technique)file_blast_radiusDetect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
AML.T0055 Unsecured Credentials (technique)credential_accessDetect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
AML.T0086 Exfiltration via AI Agent Tool Invocation (technique)network_egressDetect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments; a cohort baseline for first-time hosts
AML.TA0012 Privilege Escalation (tactic)privilege_changeDetect Evidence After the activity, not before it.a runtime whose adapter records tool-call arguments
AML.T0081 Modify AI Agent Configuration (technique)agent_config_tamperDetect Evidence After the activity, not before it.the session's working directory is known

NIST AI Risk Management Framework 1.0

These are the 13 subcategories the Compliance Pack control map evaluates (NIST AI 100-1, https://doi.org/10.6028/NIST.AI.100-1, version 1.0). The Compliance Pack is part of Pro. For a reporting period it marks each one operating (its policy is set and evidence of it working is in the period), configured (set, but nothing in the period exercised it) or not configured. Subcategories about an organisation rather than a running agent, such as impact assessments or workforce policy, are not in the map. They are out of scope, not covered.

NIST AI RMF 1.0 subcategories in the Compliance Pack map, and the evidence each reads
SubcategoryNIST textEvidence the map reads
GOVERN-1.2The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.Approval policies, tool sandbox policy, enforcement proxy settings.
GOVERN-1.5Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review.Alert rules and alert history, sampled human review, evaluation runs.
GOVERN-2.1Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.Human approval decisions, operator audit log. Reported configured, not operating, until approvals and audit entries name a person rather than the local default.
GOVERN-3.2Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems.Approval policies, human approval decisions.
GOVERN-6.1Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights.Enforcement proxy settings, third-party model provider calls.
MEASURE-2.4The functionality and behavior of the AI system and its components – as identified in the map function – are monitored when in production.Session and tool-call monitoring, alert rules and alert history.
MEASURE-2.6The AI system is evaluated regularly for safety risks – as identified in the map function.Guardrail events, loop detection, security posture scans.
MEASURE-2.7AI system security and resilience – as identified in the map function – are evaluated and documented.Hash-chained action log, security posture scans, tool or host use outside an allowlist.
MEASURE-2.10Privacy risk of the AI system – as identified in the map function – is examined and documented.Personal data, injection and credential content scans.
MANAGE-2.3Procedures are followed to respond to and recover from a previously unknown risk when it is identified.Alert rules and alert history, emergency stop, SIEM forwarding.
MANAGE-2.4Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.Emergency stop, budget blocks, human approval decisions.
MANAGE-3.1AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.Third-party model provider calls, budget blocks.
MANAGE-4.1Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.Session and tool-call monitoring, human approval decisions, task outcomes, operator audit log, alert rules and alert history.

Each Guard finding, why it maps, and where it stops

A finding with no identifier says so, and why. Every mapped finding names a test that fires on the behaviour and a test that stays quiet on ordinary work, pinned to the same commit.

stuck_loop trajectory

Why
LLM06:2026 names multi-turn tool calling loops (Scenario 7) and lists state hashing to detect recursive loops as a mitigation. ASI02 lists loop amplification as a common example. AML.T0034.002 is an agent driven into wasteful tool calls.
Limits
Detects the repetition whatever caused it; it cannot tell an adversary-induced loop from a bug. It reports; it does not cap spend.
Needs
a runtime whose adapter records tool calls
Fires on
tests/test_detectors.py test_stuck_loop_identical_calls_positive
Quiet on
tests/test_detectors.py test_stuck_loop_negative_legitimate_different_calls

no_progress trajectory

Why
LLM06:2026 mitigation 8 is detecting a session causing resource-intensive action without a clear end state. ASI02 names over-invoking costly APIs. AML.T0034.002 is an agent pushed into many tool calls that waste budget.
Limits
A busy session with no file change may be legitimate research. Cause is not attributed.
Needs
a runtime whose adapter records tool calls
Fires on
tests/test_detectors.py test_no_progress_positive
Quiet on
tests/test_detectors.py test_no_progress_negative_with_write

repeated_tool_failure trajectory

No identifier. A tool that keeps failing is a reliability signal. LLM06:2026 was considered and rejected: failures alone are not unbounded consumption.

action_discrepancy trajectory

Why
LLM07:2026 Scenario 7 is fabricated task completion. An agent carrying on after a failed tool result without retrying or acknowledging it is the precursor to that report.
Limits
Does not read the agent's final claim, so it cannot establish that a false completion was reported. The LLM 2026 v1.0 crosswalk relates LLM07 to ASI10 Rogue Agents for an agent that falsifies task completion. That link is not followed here: this finding sees only the step before a completion claim, not the falsified report or any sign of a rogue agent.
Needs
a runtime whose adapter records tool results
Fires on
tests/test_detectors.py test_action_discrepancy_positive
Quiet on
tests/test_detectors.py test_action_discrepancy_negative_retry

file_blast_radius behaviour

Why
LLM03:2026 covers agent actions destroying data through over-broad tools. ASI02 names deleting valuable data and passing rm -rf / to a shell. AML.T0101 is data destruction through an agent tool.
Limits
Reads tool-call arguments, not syscalls. A wide edit can be a correct refactor. Raised after the command ran.
Needs
a runtime whose adapter records tool-call arguments
Fires on
tests/test_detectors_behavioural.py test_blast_radius_root_delete_is_critical
Quiet on
tests/test_detectors_behavioural.py test_blast_radius_ignores_a_normal_edit_session

credential_access behaviour

Why
LLM02:2026 lists credentials and API keys as protected information. ASI03 defines agent identity to include authentication material. AML.T0055 is reading insecurely stored credentials from files, environment variables and private keys, the locations this detector matches.
Limits
Matches secret locations and token-shaped values in arguments and output; a program the agent runs that reads a secret itself is invisible. Access is not disclosure. AML.T0083 was rejected: no agent configuration file is matched.
Needs
a runtime whose adapter records tool-call arguments
Fires on
tests/test_detectors_behavioural.py test_credential_access_flags_env_file_read
Quiet on
tests/test_detectors_behavioural.py test_credential_access_ignores_env_example

network_egress behaviour

Why
ASI02 names exfiltrating information through legitimate tools. AML.T0086 is exfiltration through an agent tool that writes to a remote location, which the write-direction ground reports.
Limits
Contacting a new host is not exfiltration. Hosts are read from arguments, not network traffic. First-time hosts need a learned baseline, so a new install is silent on that ground. LLM02:2026 was not mapped: no disclosure is observed.
Needs
a runtime whose adapter records tool-call arguments; a cohort baseline for first-time hosts
Fires on
tests/test_detectors_behavioural.py test_egress_flags_a_host_absent_from_the_baseline
Quiet on
tests/test_detectors_behavioural.py test_egress_ignores_localhost

privilege_change behaviour

Why
LLM03:2026 covers agents acting with standing high privilege. ASI03 is escalating access. AML.TA0012 is the Privilege Escalation tactic; it is a tactic, not a technique, because no ATLAS technique describes sudo, setuid or IAM grants run by an agent.
Limits
Reads commands, not the resulting privilege. AML.T0105 Escape to Host was rejected: only the privileged-container pattern relates to it.
Needs
a runtime whose adapter records tool-call arguments
Fires on
tests/test_detectors_behavioural.py test_privilege_change_flags_sudo
Quiet on
tests/test_detectors_behavioural.py test_privilege_change_ignores_ordinary_commands

rate_limited silent_failure

No identifier. A provider throttling the agent is an availability symptom reported for operations; no item in these frameworks describes it.

blocked_on_user silent_failure

No identifier. An agent waiting on a person is an operational state. It is not evidence that the AML.M0029 human-in-the-loop mitigation was applied correctly.

crashed silent_failure

No identifier. A crash loop is a reliability signal; no item in these frameworks describes it.

repo_config_exec workspace

Why
ASI05 is unexpected code execution; a checkout's own git config or folder-open task runs a program during ordinary operations.
Limits
Reports the configuration, not that it ran. LLM04:2026 was rejected: its scope is the model and dataset supply chain. AML.T0011 was rejected: it concerns AI artifacts.
Needs
the session's working directory is known
Fires on
tests/test_redteam_corpus.py test_worktree_hookspath_is_flagged
Quiet on
tests/test_redteam_corpus.py test_default_hookspath_is_not_flagged

agent_config_tamper workspace

Why
AML.T0081 is modifying an agent's configuration so a change persists and affects every agent that reads it. ASI04 covers tampered artefacts an agent loads, with pinning configs as a mitigation.
Limits
Flags hook commands ClawMetry did not install; the project author may have added them on purpose. It does not show who wrote them.
Needs
the session's working directory is known
Fires on
tests/test_guard_workspace_kinds.py test_claude_hook_file_on_a_cursor_session_names_cursor
Quiet on
tests/test_guard_workspace_kinds.py test_all_clawmetry_hooks_emit_no_finding

package_manifest_exec workspace

Why
ASI05 Example 6 is a package install whose hostile code runs during installation. ASI04 covers third-party components that bring unsafe code.
Limits
Reports the install script, not that it ran or that it is hostile. AML.T0011.001 was rejected: it concerns packages presented for AI tasks.
Needs
the session's working directory is known
Fires on
tests/test_redteam_corpus.py test_an_install_hook_is_reported
Quiet on
tests/test_redteam_corpus.py test_a_publish_or_ordinary_script_is_ignored

coordinated_action fleet

Why
ASI07 includes covert channels between agents, and unrelated agents converging on one shared destination is how a shared cache becomes a message board. ASI08 names repeated identical intents across agents as an observable symptom.
Limits
Read from tool arguments, not the network. Needs several unrelated session families and a full settle window of node memory; a new node reports nothing.
Needs
several unrelated session families and a full settle window of node memory
Fires on
tests/test_detectors_coordinated_action.py test_unrelated_sessions_writing_one_unseen_prefix_fire_once
Quiet on
tests/test_detectors_coordinated_action.py test_an_orchestrator_and_its_subagents_count_once

Gaps: what Guard does not cover

  • OWASP Top 10 for LLM Applications 2026 v1.0: LLM01:2026 Prompt Injection; LLM04:2026 Supply Chain; LLM05:2026 Data and Model Poisoning; LLM08:2026 Hidden Context Exposure; LLM09:2026 Vector and Embedding Weaknesses; LLM10:2026 Improper Output Handling
  • OWASP Top 10 for Agentic Applications 2026: ASI01 Agent Goal Hijack; ASI06 Memory & Context Poisoning; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents
  • MITRE ATLAS: not enumerated. ATLAS catalogs hundreds of adversary techniques; only the identifiers in the table above are claimed.
  • Not covered by any finding: prompt content inspection, model and dataset supply chain, generated-code scanning, and memory or retrieval poisoning. Pair ClawMetry with a control built for each of these.
  • Not yet in the mapping: the pre-tool gates (tool risk classification and hook approvals), which can hold an action before it runs.

MITRE ATLAS OpenClaw case studies

A replay of MITRE ATLAS's four OpenClaw case studies against Guard is tracked in vivekchand/clawmetry#5944. Its scorecard ships in the open-source repository from clawmetry 0.12.877 (docs/ATLAS_OPENCLAW_SCORECARD.md at 0.12.880). Every result in it is a fixture replay: recorded events fed to the detectors, with no agent running and no control acting. This page does not restate those results.

Evidence bundles

The Compliance Pack, part of Pro, builds an evidence bundle from your own environment for five control maps: NIST AI RMF, SOC 2, OWASP LLM 2026, OWASP Agentic 2026 and MITRE ATLAS (clawmetry compliance bundle --framework nist-ai-rmf). The NIST AI RMF and SOC 2 maps report each control as operating, configured or not configured for the period. The OWASP and MITRE ATLAS maps report each control as exercised, configured, gap or unknown, and never as effective. Every bundle carries a printable HTML report. For how ClawMetry itself is assessed, see the trust hub and the compliance status, which says plainly that ClawMetry holds no certification.

Sample report: synthetic data, not a customer

A MITRE ATLAS evidence report and its scenario traceability export, generated by clawmetry-pro 0.7.29 with clawmetry 0.12.880 from a synthetic store of three invented sessions. The only change to what the product rendered is the label. The sample shows the format and the limits the report states. It says nothing about any real environment.