Archestra open-sources OpenAPPA security engine with 0% attack success rate
10/04/2026 — 10/05, 03:06·1 sources·1 reports
Story overview
On October 4, 2026, a DEV Community post reported that Archestra had released an open-source security engine called OpenAPPA. According to that account, the engine posted a flat zero percent attack success rate on two major security benchmarks. The post makes a point of the figure being zero rather than merely low, and repeats the number in its opening.
OpenAPPA runs outside the AI agent, the report says, and is aimed at two failure modes. The first is prompt injection, where malicious instructions sneak into an AI agent's context and trick it into leaking sensitive data. The second is data exposure that occurs when an agent hallucinates and then acts on an incorrect assumption.
That is the extent of the technical detail given. The report does not name the two benchmarks, does not say whether they are public or were run by Archestra itself, does not describe how the engine is implemented, and gives no release date beyond the announcement. It also does not specify which kinds of sensitive data or which agents are in scope.
So far this is the only coverage of the release in the available material. Nothing has been reported about independent reproductions of the benchmark result, third-party testing, or responses from other vendors, and no follow-up developments have appeared.
AI-generated from 1 reports · updated 1 hour ago
Latest turnArchestra has released OpenAPPA, an open-source security engine it says scored a flat zero percent attack success rate on two major security benchmarks. The engine runs outside the AI agent, targeting prompt injection — malicious instructions that trick an agent into leaking sensitive data — as well as exfiltration caused by agent hallucination.
- Heat index
- 86
- Sources
- 1
- Reports
- 1
- First seen
- 5 hours ago
Reports on this story headlines open the original
Archestra has released OpenAPPA, an open-source security engine it says scored a flat zero percent attack success rate on two major security benchmarks. The engine runs outside the AI agent, targeting prompt injection — malicious instructions that trick an agent into leaking sensitive data — as well as exfiltration caused by agent hallucination.
DEV Community · AIAI score 59
Other stories people are talking about
- Heat index 344Google limits free Gemini users to Flash-Lite starting October 97 sources
- Heat index 270RisingAleph Alpha releases Kolibri-1, a 78B MoE model with 1M context5 sources
- Heat index 222OpenAI safety staffer David Robinson resigns and warns in The Atlantic5 sources
- Heat index 212Meta open-sources Muse Gadgets firmware and SDK7 sources
- Heat index 144OpenAI DevDay 2026 launches Dots, Decisions API, and more3 sources
- Heat index 137Google pauses open-source bug bounty as AI hallucination reports overwhelm maintainers2 sources
How is heat calculated?About the methodHide
Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.
This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source.
- Surge
- Discussion rising fast
- New
- First report within 6 hours
- Rising
- Still gathering discussion
