Audit A2A agent cards across L1-L4 trust dimensions. Score your agent card. AgentLair is the L4 reference implementation.
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral…
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat 1 Quelldatei aus das Repository-Archiv gelesen und keine MCP-Tool-Registrierung gefunden. Die Extraktion arbeitet musterbasiert über den ausgelieferten Quellcode: ein Server, der seine Tool-Liste zur Laufzeit aufbaut oder nur gebündelten beziehungsweise minifizierten Code ausliefert, registriert nichts, was hier sichtbar wäre. Lies es als „nicht erkannt“, nicht als „legt keine offen“.
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral trust (L4). The spec has no standard for it. This tool makes that gap visible, layer by layer, in…
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.