You can't govern what you can't name: why AI agent vulnerabilities need a shared vocabulary, not just risk categories

Reddit r/AI_Agents Tools

Summary

The article introduces AVE (Agentic Vulnerability Enumeration), a tool that provides stable IDs for behavioral vulnerabilities in AI agent deployments, aiming to improve tracking and security across frameworks like OWASP, MITRE, and NIST.

Disclosure: I'm one of the people who maintains the project this is about. Most AI governance frameworks describe risk categories, excessive agency, tool misuse, memory poisoning. Useful for policy, but it doesn't give you a way to track a specific, recurring behavioral pattern across your own agent deployments, or confirm that two different security tools flagging "something wrong with this MCP server" are actually talking about the same issue. CVE and CWE solved this for regular software decades ago. A SQL injection gets a stable ID, every tool that finds it afterward references the same thing. Agentic components never had that, because CVE anchors to a package and version, and the actual problem here is a behavioral pattern in text an LLM reads and acts on, tied to neither. We built AVE (Agentic Vulnerability Enumeration) as an attempt at that missing layer, stable IDs for distinct behavioral vulnerability classes in skill files, MCP servers, and agent plugins. 80 records, each scored for severity, each mapped into OWASP MCP Top 10, MITRE ATLAS, and NIST AI RMF. The part I'd actually trust if I were reading this cold: three independent security tools, sharing no code with us or each other, have built their own crosswalks against these records unprompted, and their findings converge on the same IDs at the mechanism level, not just matching category names. That's the strongest signal we have that this holds up outside our own reasoning about it. Worth being direct about the governance side too, since it's relevant if anyone's actually deciding whether to build on this: one maintainer with real merge authority right now, that's a real limitation, not a footnote, and adding a second is an explicit, tracked goal, not an afterthought. Curious whether this maps onto problems people here are actually running into, specifically: does "which specific behavior happened" versus "which risk category does it fall under" feel like a real, practical gap in what you're building or monitoring, or does the category-level view already cover what you need day to day?
Original Article

Similar Articles

What Is an AVE Record and Why CVE Does Not Work for AI Agents?

Reddit r/AI_Agents

The article introduces the Agent Vulnerability Enumeration (AVE) record as a new standard designed to address the inadequacies of CVE for AI agent vulnerabilities, covering scoring, detection, and standardization challenges specific to agentic AI.

@ItsRoboki: https://x.com/ItsRoboki/status/2046220862546960563

X AI KOLs Timeline

A developer argues that modern AI agent terminology (harnesses, orchestrators, memory layers, etc.) is largely rebranding of familiar software engineering patterns, coining the phrase 'Vocabulary Tax' for the intimidation new jargon creates. The post aims to demystify agentic AI concepts for experienced developers.