Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy_level / memory_persistence, flags autonomous-without-IRU, destructive-on-non-autonomous, persistent-memory-without-refusal-taxonomy. Library + CLI.
Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy / memory; surfaces the governance gaps that hurt an audit — autonomous agents missing incident-response URIs, persistent-memory agents with no refusal taxonomy, destructive tools on non-autonomous agents. Status: v0.1.0 — Node 20/22 supported, library + CLI. Code | Severity | Rule | | 🔴 | but is missing (the spec requires…
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Forge ha letto 8 file sorgente da l’archivio del repository e non ha trovato alcuna registrazione di strumenti MCP. L’estrazione si basa su schemi applicati al codice distribuito: un server che costruisce l’elenco degli strumenti a runtime, o che distribuisce solo codice impacchettato o minificato, non registra nulla di visibile qui. Va letto come «non rilevato», non come «non ne espone nessuno».
Fleet-analyze a directory of A2A AgentCard documents. Counts by autonomy / memory; surfaces the governance gaps that hurt an audit — autonomous agents missing incident-response URIs, persistent-memory agents with no refusal taxonomy, destructive tools on non-autonomous agents. Status: v0.1.0 — Node 20/22 supported, library + CLI. Code | Severity | Rule | | 🔴 | but is missing (the spec requires the conjunction). | | 🔴 | Autonomous agent with no entries. | | 🟠 | Agent declares destructive…
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.