Audit A2A agent cards across L1-L4 trust dimensions. Score your agent card. AgentLair is the L4 reference implementation.
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral…
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Forge ha letto 1 file sorgente da l’archivio del repository e non ha trovato alcuna registrazione di strumenti MCP. L’estrazione si basa su schemi applicati al codice distribuito: un server che costruisce l’elenco degli strumenti a runtime, o che distribuisce solo codice impacchettato o minificato, non registra nulla di visibile qui. Va letto come «non rilevato», non come «non ne espone nessuno».
Score any A2A agent card on identity, authentication, authorization, and behavioral trust. Zero install. One npx away. Embed a live trust grade in your README: Encode your card URL: Paste the output into the badge URL. It re-audits hourly — your grade stays current without any CI. The A2A protocol tells agents how to talk. It doesn't tell them how to trust. Most agent cards score 0% on behavioral trust (L4). The spec has no standard for it. This tool makes that gap visible, layer by layer, in…
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.