--- license: apache-2.0 language: - de - en metrics: - f1 - precision - recall base_model: - jhu-clsp/mmBERT-small pipeline_tag: text-classification tags: - tool-use - ai-agents - function-calling - mcp - tool-security - security - llm-security - ai-safety - ai-agent-security - patronus - multilingual - modernbert - onnx --- # Model Card for Husky Sight Tool Type Classifier **Multilingual Tool-Type Classifier for Real-World AI Agent Security** Husky Sight is a multilingual ModernBERT-based ([mmBERT](https://huggingface.co/blog/mmbert)) classifier that identifies *which kind of tool* a request, tool call, or agent step involves. It is part of the Patronus Protect security stack and is a member of the Husky tool-analysis family, alongside [Husky Paw](https://huggingface.co/patronus-studio/husky-paw-tool-action-classifier) (operation) and [Husky Nose](https://huggingface.co/patronus-studio/husky-nose-tool-security-properties-classifier) (security properties). ## Intended Uses The model maps an input text to exactly one class: | id | label | description | |---:|---|---| | 0 | `file` | Tool operating on the local file system. | | 1 | `database` | Tool operating on a database. | | 2 | `vcs` | Tool operating on version control. | | 3 | `api` | Tool operating on an API. | | 4 | `memory` | Tool operating on persistent memory. | | 5 | `messaging` | Tool operating on a messaging service. | | 6 | `web` | Tool operating on the web. | | 7 | `browser` | Tool operating on a browser. | | 8 | `shell` | Tool operating on a shell / OS command. | | 9 | `code` | Tool operating on code execution. | | 10 | `system` | Tool operating on the operating system. | | 11 | `secrets` | Tool operating on secrets / credentials. | | 12 | `infra` | Tool operating on infrastructure (k8s, cloud). | | 13 | `unknown` | Tool operating on an unidentified tool. | Examples: | Input | Expected class | |---|---| | Read the config file at /etc/app.conf | `file` | | SELECT email FROM users WHERE id = 1 | `database` | | Create a branch and open a pull request | `vcs` | | Send a POST request to the payments API | `api` | | Run `kubectl scale deployment web --replicas=3` | `infra` | | How are you today? | `unknown` | Typical downstream uses: - tool-risk routing, - AI agent policy enforcement, - approval workflows, - runtime monitoring. ## Limitations - A positive prediction describes an apparent property of the input, not proof that an action was executed. - The model does not track information flow across multiple agent steps. - German and English are the primary evaluated languages; other languages run through the multilingual backbone but were not actively validated. - False positives and negatives are possible. High-impact enforcement should combine the model with deterministic policy and calibrated thresholds. ## Model Variants - **Husky Sight Tool Type Classifier** – full ModernBERT model in FP32 (`model.safetensors`). - **Husky Sight Tool Type Classifier ONNX (FP16)** – `onnx/onnx_fp16/model_fp16.onnx` in this repository. - **[Husky Sight Tool Type Classifier Edge](https://huggingface.co/patronus-studio/husky-sight-tool-type-classifier-edge)** – quantized ONNX builds (`int8`, `int8_int4_embeddings`, `fp16`) in a separate edge repository. - **Husky Sight Tool Type Classifier NTDB L2** – lightweight multilingual cascade components under `l2/` for efficient local runtime classification. ## Training Data Trained on Patronus' in-house multilingual dataset for this task, built from cleaned real-world sources plus internally generated examples. Real-world sources were judge-cleaned by content (no keyword heuristics) and contaminated rows removed. ### Augmentations To improve robustness the dataset includes modern obfuscation techniques: - Unicode variants - Homoglyph attacks - Encodings (e.g. base64) - Tag wrappers (User:, System:) - HTML tags - Code comments - Spacing noise - Leetspeak - Case noise - Combination of N augmentation techniques ### Regularization - Natural-language wrappers around the payload - Counterfactual samples - Trigger-word / spurious-correlation corpora - ~90% similarity deduplication with a train/(val ∪ test) leakage guard ### Reducing bias All augmentations and regularizers are applied to positive and negative examples alike so the model keys on content rather than surface form. ## Benchmark Held-out test set (n = 2,914), single-label: | Metric | Score | |---|---| | **Accuracy** | **0.957** | | **F1 (macro)** | **0.957** | | Precision (macro) | 0.957 | | Recall (macro) | 0.957 | Per-class F1: | Class | F1 | |---|---| | database | 0.992 | | secrets | 0.990 | | messaging | 0.984 | | infra | 0.981 | | code | 0.981 | | memory | 0.980 | | browser | 0.977 | | file | 0.975 | | vcs | 0.974 | | unknown | 0.938 | | web | 0.936 | | system | 0.904 | | shell | 0.891 | | api | 0.890 | ## Usage ```python from transformers import pipeline clf = pipeline("text-classification", model="patronus-studio/husky-sight-tool-type-classifier") clf("Run kubectl scale deployment web --replicas=3") # -> [{"label": "infra", "score": 0.98}] ``` ## ONNX The FP16 ONNX export lives under `onnx/onnx_fp16`; the quantized builds (`int8`, `int8_int4_embeddings`) live in the separate [Husky Sight Tool Type Classifier Edge](https://huggingface.co/patronus-studio/husky-sight-tool-type-classifier-edge) repository. Apply a softmax over the logits and take the argmax: ```python from optimum.onnxruntime import ORTModelForSequenceClassification from transformers import AutoTokenizer model_id = "patronus-studio/husky-sight-tool-type-classifier" tokenizer = AutoTokenizer.from_pretrained(model_id) model = ORTModelForSequenceClassification.from_pretrained(model_id, subfolder="onnx/onnx_fp16", file_name="model_fp16.onnx") inputs = tokenizer("Run kubectl scale deployment web --replicas=3", return_tensors="pt") logits = model(**inputs).logits.detach().cpu().numpy()[0] print(model.config.id2label[int(logits.argmax())]) ``` ## Citation ```bibtex @misc{huskysight2026, title={Husky Sight Tool Type Classifier: Multilingual Classification for Real-World AI Agent Security}, author={Patronus Protect}, year={2026}, howpublished={\url{https://huggingface.co/patronus-studio/husky-sight-tool-type-classifier}} } ``` ## License This model is released under the [Apache License 2.0](https://www.apache.org/licenses/LICENSE-2.0). A copy of the license is included as `LICENSE` in this repository. The model is derived from [jhu-clsp/mmBERT-small](https://huggingface.co/jhu-clsp/mmBERT-small), which is distributed under the **MIT License**. The upstream copyright and permission notice are retained; the MIT terms continue to apply to the portions originating from that work. ## Patronus Ark This model is built to run inside **Patronus Ark**, Patronus' open-source on-device AI-security scanning library (L1 native rules → L2 NTDB cascade → L3 transformer). Ark is not publicly released yet — a repository link will be added here at launch. --- ## 🛡️ Patronus Protect Brought to you by [Patronus Protect](https://patronus.studio) — a local AI firewall that secures every AI interaction, including prompts, tools and documents, before it reaches your models. Try it for free at [patronus.studio](https://patronus.studio).