Skip to content
MoorAI
// moorai vs uber adr

MoorAI vs Uber ADR

Last updated

ADR reads what an AI agent did. MoorAI decides what it may do next. ADR (Agentic AI Detection and Response) is an open-source project from Uber under the Apache-2.0 licence, described in a paper accepted to MLSys 2026. Its README calls it “an enterprise security system for AI agents.” (github.com/uber/ADR) Its sensor “parses logs from multiple AI agent platforms and normalizes them into a unified schema for downstream analysis,” (ADR Sensor README) and its detector reviews each session with a triage model and, for suspicious sessions, a reasoning agent. MoorAI is a PreToolUse hook inside the coding agent and an MCP proxy in front of the tool servers. It checks each tool call and prompt before it runs, scans what comes back, and coaches, masks or blocks on the device.

ADR is not a vendor product. Uber built it for its own fleet and runs it in production, “for over ten months across 7,200+ hosts processing 10,000+ daily sessions.” (ADR paper, arXiv 2605.17380) It costs nothing, its code is open and its paper is peer reviewed. The difference this page is about is timing: ADR’s open-source release detects once a session has been written to disk, and MoorAI acts before the step runs. MoorAI decides against a 77-threat matrix and by default sends only category · risk · keyed one-way hash (plus the login and hostname, which the console pseudonymises on arrival).

ADR does several things MoorAI does not. It reads the logs of eleven agents with no hook in any of them, inventories a device’s AI tooling with a ledger of what it could not see, and reasons over a whole session with a language model. Those rows are further down.

Three things this page does not state. (1) A head-to-head score. ADR publishes ADR-Bench, a benchmark of 300+ tasks across 134 MCP servers. This page states no result for MoorAI on ADR-Bench, and none for ADR on MoorAI’s benchmark. (2) ADR Prevention. ADR’s README says this component is not in the current open-source release, so what it will do is not described here. (3) Uber’s backend. In the paper the sensor forwards telemetry to backend systems that are not in the repository; this page describes the open-source code and what the paper reports. Every ADR statement below is quoted from ADR’s repository or its paper, and the source is named.

The core difference is when the decision is made: after the session is on disk, or before the step runs.

01When does each decide?
ADR’s paper: “The sensor runs on an hourly schedule with minimal overhead” (0.182 seconds a run on average), and the Sensor README tells operators to “Schedule runs and monitor last-seen health externally.” Detection follows once the session reaches the backend. The paper is direct about what that timing cost Uber: “by the time detections were surfaced, credentials had often already been exposed externally, creating irreversible risk.” (ADR paper, §6.2) That finding led Uber to add a prevention layer “executed as a pre-prompt hook” that finds secrets in prompts with regex and entropy thresholds. MoorAI’s hook runs on every tool call: a .env read, a secret in an MCP argument or a call to an unapproved MCP server is blocked before it reaches the agent once the device is enrolled in a console, and an unenrolled device coaches only. It also checks shell commands, file writes and edits, web fetches and sub-agent prompts, and on Claude Code it scans command output, MCP responses and fetched pages as they come back.
02What leaves the machine?
ADR’s Sensor README: “The OpenTelemetry exporter applies no redaction or field projection, so prompts, responses, tool arguments, tool results, usernames, hostnames, and local paths can be transmitted.” It also says to “Treat sensor output as sensitive data.” That follows from the design: reasoning over a session needs the session. Uber’s deployment wraps controls around it; the paper says secrets are redacted from stored telemetry “where possible,” access is limited to security personnel, and telemetry is retained for 13 months. The open-source detector calls hosted models: its Detection README names gpt-4o for triage and claude-sonnet-4-6 for the reasoning agent. MoorAI checks content on the device and by default sends the console a category, a risk level and a keyed one-way hash (plus the login and hostname, which the console pseudonymises on arrival); content is kept only if an administrator enables a capture tier. The agent is MIT, so that claim can be checked in code.
03What does a decision cost?
ADR’s detector has two tiers, “high-recall triage with deeper agentic reasoning for suspicious sessions.” (github.com/uber/ADR) On ADR-Bench the paper reports “$0.024 per task with 18.5s average latency,” with 40.7% of tasks settled by triage alone. That is inexpensive for an investigation, and at 18.5 seconds a task it is built to run after the session rather than to hold a tool call open. MoorAI decides deterministically on the device, with no model call by default; an on-device model second opinion is opt-in and off by default. Its README measures a p50 of 1.99 ms per PreToolUse in process through @moorai/agent-sdk, 6.4–11 ms per scan through the localhost sidecar, and 164–309 ms per tool call for the shell hook, which starts one process per call. The trade-off is real, and Uber’s paper names it: simple non-LLM checks work for static patterns such as secrets “but fail for attacks requiring reasoning about tool semantics, causal context, and enterprise policies.” (ADR paper, §6.2)
✓ yes ◐ partial — unconfirmed ✗ no

Where MoorAI holds ground ADR does not

These rows follow from sitting inside the agent before each step runs, and deciding on the device. ADR marks describe the open-source release, with Uber’s deployment noted where the paper describes it.

MoorAI ADR
Blocks a risky action before it runs ✓PreToolUse hook and MCP proxy, once enrolled ◐not in the open-source release; at Uber, a regex pre-prompt hook for secrets
Checks shell commands, file reads, MCP arguments and results before they take effect ✓ ✗read from agent logs after the fact; hourly at Uber
By default only category · risk · keyed one-way hash (plus login and hostname, pseudonymised on arrival) leave the device ✓capture tiers are opt-in, admin-enabled ✗OTLP export applies no redaction or field projection
Enforces on MCP traffic inline, refusing a call before the server sees it ✓stdio proxy; HTTP gateway, run against a real remote MCP server ✗MCP calls seen in transcripts; MCP-gateway prevention is future work in the paper
MCP server allow-list with approval, a 0–100 reputation score and a pre-install scan ✓ ◐Discovery inventories MCP servers and flags unknown ones for review
Declared workload profiles: a call outside a service’s expected tools, MCP servers or hosts is reported or denied ✓not evaluated by the HTTP MCP gateway —the detector reasons with MCP-policy context; no per-workload profile described
Covers agents in CI jobs, containers and Agent SDK services ✓server mode, in-process SDK hook, sidecar and container image ◐Uber observes internal automation; open-source Discovery does not cover containers or cloud agents
Decides deterministically on the device, in milliseconds, with no model call ✓on-device model second opinion is opt-in ✗triage model, then a reasoning agent; $0.024 and 18.5 s per ADR-Bench task
Coaches the developer with the safer way, at the moment of the action ✓ ✗alerts go to a human review queue

Where ADR covers ground MoorAI does not

These follow from reading what agents leave on disk, and reasoning over it afterwards. No hook has to be installed in the agent, nothing has to be decided in milliseconds, and the whole session is in view.

MoorAI ADR
Reads the local logs of 11 agents, with no hook or plug-in inside any of them ◐hooks in 5 agents; validated end to end on Claude Code ✓Claude Code, Cursor, Cline, Claude Desktop, Codex CLI, Copilot CLI, DeepSeek Harness, Warp, opencode, Gemini CLI, Antigravity
Sees past sessions, including ones from before it was installed ✗sees what passes its hook or proxy while installed ✓14-day default lookback
Language-model reasoning over a whole session, with source-code, MCP-policy and threat-intel context ◐deterministic session rules, such as outbound action after untrusted content ✓
Reads an MCP tool’s source code when judging what a session did ✗checks each call and result; an opt-in pre-install scan reads package code for install-time patterns ✓source-code inspection is one of the reasoning agent’s context providers
Device inventory with a coverage ledger that reports what it could not see ◐AI bill of materials checked against an allow-list ✓ADR Discovery
Everything released is open source and free, with no licence to buy ◐agent MIT; console source-available, free to 200 users ✓Apache-2.0
A peer-reviewed paper and a published production deployment ✗a public benchmark and harness; no peer-reviewed paper ✓MLSys 2026; 7,200+ hosts at Uber
Customer-facing agents, such as AI support agents ◐built for coding agents; a localhost sidecar for other agent loops ✓in Uber’s deployment, per the README

Same capability, different mechanism

Both projects do each of these, so the table describes how rather than scoring.

MoorAI does it by… ADR does it by…
Stopping a secret before it leaves A provider-anchored secrets engine (about 14 provider families plus entropy scoring) on prompts, file reads, commands, MCP arguments and output. A mask replaces the secret with a content-free placeholder and lets the call proceed. At Uber, “a regex-based detection mechanism using both pattern matching and entropy thresholds” in a pre-prompt hook for Cursor and Claude Code: 97.2% precision, 206 true positives and 6 false positives across 212 unique credentials. (ADR paper, §6.2)
Watching MCP A stdio MCP proxy and an HTTP MCP gateway that check tool calls and results inline. Its own README states the bound: the proxy refused 12 of 12 malicious actions in a test set, but only 4 of the 12 travel over MCP at all, so the hook is the main control. MCP calls read from session transcripts. The paper argues gateways “require changes to MCP hosts, are incompatible with streaming responses, and capture only partial information,” and lists “adaptive real-time prevention at the MCP gateway layer” as future work.
Finding AI tools on a device An on-device AI bill of materials: models, MCP servers with a reputation score, editor extensions, running local model servers and AI keys at rest, checked against your allow-list. ADR Discovery inventories AI apps, CLI agents, IDE extensions, model runtimes and MCP servers and “reports coverage gaps so an incomplete scan is not mistaken for a clean machine.” (ADR Discovery README)
Sending events to an observability stack OpenTelemetry export of the same content-free events the console receives. OpenTelemetry logs whose body is the whole normalised session record.
A public benchmark Open corpora and a harness anyone can score a product against: agentic security benchmark. ADR-Bench: “300+ tasks, 134 MCP servers, and coverage of all 17 agent attack techniques,” plus an AgentDojo integration. (github.com/uber/ADR)

Where MoorAI is stronger. Timing and data. The file read, the shell command, the MCP argument and result, and the prompt are checked before they take effect, on the device, deterministically and in milliseconds to a few hundred milliseconds, with no model call by default. The console receives no content, the code that guarantees that is MIT, and the same engine runs in CI jobs, containers and Agent SDK services through server mode.

Where ADR is stronger. Reach and hindsight. It reads eleven agents’ logs without a hook in any of them, including sessions from before it was installed, inventories AI tooling with an honest ledger of its gaps, and reasons over a whole session with source code, MCP policy and threat intelligence in view. Its reasoning agent reads an MCP tool’s source code, which “reveals what an MCP tool actually does by examining its implementation,” (ADR paper, §3.2) and that catches attacks that live in a server’s behaviour rather than in any single call. MoorAI checks each call before it runs, scans results as they come back, and does not read a server’s code when it decides; its opt-in pre-install scan reads a package’s code for install-time patterns, which is a different question. It is free and Apache-2.0 throughout, and its claims are backed by a peer-reviewed paper and a deployment of more than 7,200 hosts.

Which to run where. They compose. Run ADR where the question is what happened: investigating sessions after the fact across a fleet, including agents MoorAI does not hook, with a language model doing the reading. Run MoorAI where the action has to be stopped before it runs, on developer machines and, in server mode, in the CI jobs and containers where Claude Code or an Agent SDK service runs, and where the record should hold no prompt content. Nothing in either project’s documentation says they conflict on one machine: ADR reads the transcript files an agent writes and MoorAI runs in the agent’s hooks. We have not run them together.

Questions about MoorAI and Uber ADR

Is Uber ADR a commercial product?

No. ADR is an open-source project from Uber, an end-user company, released under the Apache-2.0 licence on GitHub. Uber runs it in production: its MLSys 2026 paper reports more than ten months across 7,200+ hosts processing 10,000+ sessions a day. There is no licence to buy. MoorAI’s agent is also open source, under MIT; its console is source-available under the Elastic License 2.0 and free up to 200 users.

Can ADR block a coding agent’s action before it runs?

Not in the open-source release. ADR’s README says the ADR Prevention component is not included in the current open-source release. Its sensor parses agent logs that are already written, on an hourly schedule in Uber’s deployment, and its detector then analyses the session. At Uber, prevention is a regex and entropy pre-prompt hook for secrets, which the paper reports at 97.2% precision. MoorAI checks each tool call and prompt before it runs and scans tool and MCP results as they come back, through the agent’s PreToolUse hook and an MCP proxy, and blocks once a device is enrolled in a MoorAI console.

What does each send off the machine?

ADR’s sensor forwards normalised session telemetry for analysis, and its README says the OpenTelemetry exporter applies no redaction or field projection, so prompts, responses, tool arguments, tool results, usernames, hostnames and local paths can be transmitted. Uber’s paper says secrets are redacted from stored telemetry where possible and telemetry is kept for 13 months. MoorAI sends a category, a risk level and a keyed one-way hash (plus the login and hostname, which the console pseudonymises on arrival) by default, and keeps content only if an administrator enables a capture tier.

Does MoorAI replace ADR, or the other way round?

No. ADR reads the logs of 11 agents without a hook in any of them and reasons over whole sessions with language models, which suits investigation after the fact across a fleet. MoorAI sits inside the agent and stops a risky action before it runs, deciding on the device and, by default, without a model call. Run ADR where the question is what happened across sessions, and MoorAI where the action has to be stopped and the record has to hold no prompt content.

ADR capabilities are taken from ADR’s own repository and paper, read on 6 October 2026 at commit ea8182e: the README, the Sensor README, the Discovery README and its package documentation (which lists “WSL, containers, remote/cloud agents, scheduled agents” among what is not implemented), the Detection README, and the paper, ADR: An Agentic Detection System for Enterprise Agentic AI Security (MLSys 2026, industry track). Every quoted phrase is ADR’s. MoorAI figures are from the MoorAI README at v1.3.2. ◐ = partial: present but narrower than the other column. — = unconfirmed, not necessarily absent. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. MoorAI’s hook fails open if it crashes or times out: it is governance, not a sandbox. Server mode has been seen working in one live claude -p run; an Agent SDK service and a GitHub Actions run have not been watched end to end. The agent is MIT and runs on macOS and Windows; the console is source-available under the Elastic License 2.0 and free up to 200 users. Uber is a trademark of its owner; this page is independent and is not affiliated with or endorsed by Uber. Both projects change, so check specifics against current documentation.