InfoQBruno Couriol4 min readintermediate
New Archestra's OpenAPPA Saturates Two Major Security Benchmarks with a 0% Attack Success Rate
Summary
OpenAPPA is an open‑source security engine that sits outside an LLM agent’s prompt loop and enforces deterministic data‑flow policies via a TOML policy file. In the Bench‑Corp and AgentThreatBench evaluations it achieved 0 % attack success with 89 % task completion, outperforming Claude Code auto‑mode and Microsoft FIDES.
- APPA uses a lattice‑based policy algebra (audience, trust, authority) expressed in a single `appa.toml` file to enforce monotonic restrictions on tool calls.
- The engine runs external to the agent, preventing the model from inspecting or bypassing policy checks.
- Recovery mechanisms (sanitizers, authorities, disposable child branches) let agents continue work after a blocked action while preserving security.
- Bench‑Corp and AgentThreatBench show OpenAPPA blocks all simulated data‑exfiltration attacks and retains 89 % task success, versus 10 %–31 % breach rates for competing solutions.
Teams building LLM‑driven agents need a practical way to enforce data‑exfiltration protection without crippling utility.
7/10

