Audit A2A agent cards across L1-L4 trust dimensions. Score your agent card. AgentLair is the L4 reference implementation.
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral…
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Forge a lu 1 fichier source de l’archive du dépôt et n’a trouvé aucun enregistrement d’outil MCP. L’extraction repose sur des motifs appliqués au code livré : un serveur qui construit sa liste d’outils à l’exécution, ou qui ne livre que du code empaqueté ou minifié, n’enregistre rien de visible ici. À lire comme « non détecté », pas comme « n’en expose aucun ».
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral trust (L4). The spec has no standard for it. This tool makes that gap visible, layer by layer, in…
Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.