Model Card for Husky Paw Tool Action Classifier

Multilingual Tool-Operation Classifier for Real-World AI Agent Security

Husky Paw is a multilingual ModernBERT-based (mmBERT) classifier that identifies which operation a tool request performs. It is part of the Patronus Protect security stack and is a member of the Husky tool-analysis family, alongside Husky Sight (tool type) and Husky Nose (security properties).

Intended Uses

The model maps an input text to exactly one class:

id label description
0 read Reads or retrieves data.
1 write Creates or modifies data.
2 list Lists or enumerates items.
3 exec Executes code or a command.
4 network Sends or receives over the network.
5 unknown No identified operation.

Examples:

Input Expected class
Read the contents of report.pdf read
Save the summary to the team folder write
List all files in the reports directory list
Run the migration script exec
POST the payload to the remote endpoint network
Let's chat about the weather unknown

Typical downstream uses:

  • tool-risk routing,
  • execution-gate decisions,
  • approval workflows,
  • runtime monitoring.

Limitations

  • A positive prediction describes an apparent property of the input, not proof that an action was executed.
  • The model does not track information flow across multiple agent steps.
  • German and English are the primary evaluated languages; other languages run through the multilingual backbone but were not actively validated.
  • False positives and negatives are possible. High-impact enforcement should combine the model with deterministic policy and calibrated thresholds.

Model Variants

  • Husky Paw Tool Action Classifier – full ModernBERT model in FP32 (model.safetensors).
  • Husky Paw Tool Action Classifier ONNX (FP16)onnx/onnx_fp16/model_fp16.onnx in this repository.
  • Husky Paw Tool Action Classifier Edge – quantized ONNX builds (int8, int8_int4_embeddings, fp16) in a separate edge repository.
  • Husky Paw Tool Action Classifier NTDB L2 – lightweight multilingual cascade components under l2/ for efficient local runtime classification.

Training Data

Trained on Patronus' in-house multilingual dataset for this task, built from cleaned real-world sources plus internally generated examples. Real-world sources were judge-cleaned by content (no keyword heuristics) and contaminated rows removed.

Augmentations

To improve robustness the dataset includes modern obfuscation techniques:

  • Unicode variants
  • Homoglyph attacks
  • Encodings (e.g. base64)
  • Tag wrappers (User:, System:)
  • HTML tags
  • Code comments
  • Spacing noise
  • Leetspeak
  • Case noise
  • Combination of N augmentation techniques

Regularization

  • Natural-language wrappers around the payload
  • Counterfactual samples
  • Trigger-word / spurious-correlation corpora
  • ~90% similarity deduplication with a train/(val ∪ test) leakage guard

Reducing bias

All augmentations and regularizers are applied to positive and negative examples alike so the model keys on content rather than surface form.

Benchmark

Held-out test set (n = 2,914), single-label:

Metric Score
Accuracy 0.946
F1 (macro) 0.937
Precision (macro) 0.936
Recall (macro) 0.938

Per-class F1:

Class F1
write 0.962
exec 0.953
read 0.945
list 0.940
network 0.926
unknown 0.893

Usage

from transformers import pipeline

clf = pipeline("text-classification", model="patronus-studio/husky-paw-tool-action-classifier")
clf("Run the migration script")
# -> [{"label": "exec", "score": 0.98}]

ONNX

The FP16 ONNX export lives under onnx/onnx_fp16; the quantized builds (int8, int8_int4_embeddings) live in the separate Husky Paw Tool Action Classifier Edge repository. Apply a softmax over the logits and take the argmax:

from optimum.onnxruntime import ORTModelForSequenceClassification
from transformers import AutoTokenizer

model_id = "patronus-studio/husky-paw-tool-action-classifier"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = ORTModelForSequenceClassification.from_pretrained(model_id, subfolder="onnx/onnx_fp16", file_name="model_fp16.onnx")

inputs = tokenizer("Run the migration script", return_tensors="pt")
logits = model(**inputs).logits.detach().cpu().numpy()[0]
print(model.config.id2label[int(logits.argmax())])

Citation

@misc{huskypaw2026,
  title={Husky Paw Tool Action Classifier: Multilingual Classification for Real-World AI Agent Security},
  author={Patronus Protect},
  year={2026},
  howpublished={\url{https://huggingface.co/patronus-studio/husky-paw-tool-action-classifier}}
}

License

This model is released under the Apache License 2.0. A copy of the license is included as LICENSE in this repository.

The model is derived from jhu-clsp/mmBERT-small, which is distributed under the MIT License. The upstream copyright and permission notice are retained; the MIT terms continue to apply to the portions originating from that work.

Patronus Ark

This model is built to run inside Patronus Ark, Patronus' open-source on-device AI-security scanning library (L1 native rules → L2 NTDB cascade → L3 transformer). Ark is not publicly released yet — a repository link will be added here at launch.


🛡️ Patronus Protect

Brought to you by Patronus Protect — a local AI firewall that secures every AI interaction, including prompts, tools and documents, before it reaches your models.

Try it for free at patronus.studio.

Downloads last month
5
Safetensors
Model size
0.1B params
Tensor type
F32
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for patronus-studio/husky-paw-tool-action-classifier

Quantized
(264)
this model
Quantizations
1 model

Collection including patronus-studio/husky-paw-tool-action-classifier