AgentAvow Trust
Signed, offline-verifiable safety scores for the MCP servers, packages & tools an agent connects to
- 0.6.2
- Version
- remote + pypi
- Transport
- 8
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 8 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (8)
scan_repo
Scan a public GitHub repository with AgentAvow and return whether it is safe for an agent to connect to: one of three answers with its reason (Safe to connect, Review before you connect, or Do not connect), a 0-100 trust score, an adoption score from real usage (stars), the findings behind it (with where and how to fix), and a signed, offline-verifiable attestation. Read-only, no account. Calls the AgentAvow public API at agentavow.com.
scan_package
Scan a published package (npm, PyPI, crates, Docker, or Hugging Face) with AgentAvow. Returns one of three answers with its reason (Safe to connect, Review before you connect, or Do not connect), a 0-100 trust score, an adoption score from real usage (downloads per week), findings with remediation, and a signed attestation. Also reports published advisories that affect the scanned version, the maintainer's deprecation notice, repo-vs-artifact drift (files shipped that aren't in the source), and AgentAvow's behavioral sandbox results when available. Scans the latest version unless `version` (or a pin in the name) names one. Read-only; calls agentavow.com.
scan_mcp_server
Scan a live MCP server's tool definitions for tool-poisoning, prompt-injection, invisible-unicode, and manifest-execution risks before your agent connects to it. Returns one of three answers with its reason (Safe to connect, Review before you connect, or Do not connect), a 0-100 trust score, findings, and a signed attestation. Read-only; calls the agentavow.com public API.
verify_trust
Verify an AgentAvow entity's trust score. Returns trust_score (0-1), trust_score_pct (0-100), trust_tier, and whether it meets a minimum threshold. Read-only, no auth. Use before interacting with an unknown agent.
check_interaction_safety
Check whether it is safe to interact with another agent by trust threshold. Thresholds: delegate 0.6, trade 0.5, collaborate 0.4, follow 0.1. Returns is_safe, risk_level, the score, and a recommendation. Read-only, no auth.
lookup_identity
Look up an AgentAvow entity by W3C DID or display name. Returns the entity's id, name, type, trust score and tier. Read-only, no auth. Use to resolve an identity before checking its trust.
get_trust_badge
Get an embeddable AgentAvow trust badge (SVG) for an entity, with ready-to-paste Markdown and HTML. The badge auto-updates as the score changes. Read-only, no auth.
about_agentavow
What AgentAvow is, which tool to use for what, how to read a verdict, and example scans. Call this for an overview or when getting started. No input, read-only.