# Install agent-threat-rules with npm

Open detection standard -- like Sigma, but for AI agents. Executable rules for prompt injection, tool poisoning, context exfiltration, and MCP attacks. Shipped in Cisco AI Defense. MIT-licensed. Version 4.0.0 via npm; verified 2026-08-23.

## Install

```sh
sudo av install npm:agent-threat-rules
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g agent-threat-rules
```

  Evidence: local npm package metadata

## Package facts

- **Package key:** npm:agent-threat-rules
- **Package manager:** npm
- **Version:** 4.0.0
- **Source summary:** Open detection standard -- like Sigma, but for AI agents. Executable rules for prompt injection, tool poisoning, context exfiltration, and MCP attacks. Shipped in Cisco AI Defense. MIT-licensed.
- **Homepage:** <https://github.com/Agent-Threat-Rule/agent-threat-rules>
- **Upstream docs:** <https://github.com/Agent-Threat-Rule/agent-threat-rules>
- **Last updated:** 2026-08-23T01:51:06.952Z
- **Generated:** 2026-09-19T06:45:57+00:00

## Executables

- agent-threat-rules (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-09-19
- Package-manager version: 4.0.0

## Security Notes

No matching local secret-handling manifest was found for agent-threat-rules. Package metadata is still published here so future coverage has a stable package URL.



## Related links

- [AI and agent packages](https://pkg.so/ai-agent-tools/) - Matched curated package taxonomy and local package facts.
- [agent-react-devtools](https://pkg.so/npm/agent-react-devtools/) - Package names and metadata indicate a similar tool family. Shared terms: agent, agents, ai.
- [agent-tars](https://pkg.so/cask/agent-tars/) - Local package facts share a topical domain. Shared terms: agent, agents, ai.
- [agent-sanitizer](https://pkg.so/npm/agent-sanitizer/) - Package names and metadata indicate a similar tool family. Shared terms: agent, injection.

## Sources

- pkg.so package database
- package relationship graph
- cross-ecosystem install command graph
