Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy_level / memory_persistence, flags autonomous-without-IRU, destructive-on-non-autonomous, persistent-memory-without-refusal-taxonomy. Library + CLI.
Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy / memory; surfaces the governance gaps that hurt an audit — autonomous agents missing incident-response URIs, persistent-memory agents with no refusal taxonomy, destructive tools on non-autonomous agents. Status: v0.1.0 — Node 20/22 supported, library + CLI. Code | Severity | Rule | | 🔴 | but is missing (the spec requires…
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat 8 Quelldateien aus das Repository-Archiv gelesen und keine MCP-Tool-Registrierung gefunden. Die Extraktion arbeitet musterbasiert über den ausgelieferten Quellcode: ein Server, der seine Tool-Liste zur Laufzeit aufbaut oder nur gebündelten beziehungsweise minifizierten Code ausliefert, registriert nichts, was hier sichtbar wäre. Lies es als „nicht erkannt“, nicht als „legt keine offen“.
Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy / memory; surfaces the governance gaps that hurt an audit — autonomous agents missing incident-response URIs, persistent-memory agents with no refusal taxonomy, destructive tools on non-autonomous agents. Status: v0.1.0 — Node 20/22 supported, library + CLI. Code | Severity | Rule | | 🔴 | but is missing (the spec requires the conjunction). | | 🔴 | Autonomous agent with no entries. | | 🟠 | Agent declares destructive…
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.