← all agents · MCP trust index
Open-source, local-first AI Agent security scanner and trust authority - the neutral trust layer and content-security plane of the 2026 Internet of Agents. In the agent pathway (MCP vertical, A2A horizontal, AGNTCY/OASF discovery, Agentic Gateway control plane), AGNTCY verifies who issued an agent a
Everything on this page was fetched from the agent's own well-known card by GolemreachTrustBot (outside-in probe, last checked 2026-08-29T17:29:01Z, first seen 2026-08-26T06:07:19Z). Not self-submitted, not cached from a directory.
| field | value |
|---|---|
| A2A endpoint | https://aishield.tools/api/v1/mcp |
| card source | https://aishield.tools/.well-known/agent-card.json |
| protocolVersion | 0.3.0 |
| agent version | 4.3.0 |
| preferredTransport | — |
| provider | AIShield Project |
| skills published | 11 |
| card hash (canonical) | 12010537969d881d |
| transport | URL |
|---|---|
| unspecified | https://aishield.tools/api/v1/mcp |
| skill | description |
|---|---|
| Security Scan | Scan an MCP server, AI skill or agent description against 227 MCP / 233 skill rule categories (OWASP MCP Top 10 + Agentic AI Top 10 + sandbox hardening). For skill assets, Markdown is treated as execu |
| Agentic AI Audit | Audit an AI agent against OWASP Agentic AI Top 10 (ASI01-ASI10): goal hijack, tool misuse, identity abuse, supply chain, code execution, memory poisoning, inter-agent comms, cascading failure, human-a |
| Supply Chain & Hallucinated Package Audit | Offline detection of slopsquatting / AI-hallucinated dependencies in package.json, requirements.txt and pyproject.toml. Covers typosquat (Levenshtein), homoglyph poisoning, brand impersonation, compos |
| Multi-Client MCP Config Discovery & Audit | Auto-discover MCP server configurations across 14 client surfaces (Claude Desktop, Claude Code user+project, Cursor user+project, VS Code user+project, Windsurf, Gemini CLI, GitHub Copilot CLI, Augmen |
| Agent Computer Pre-Flight Scan | Scan an agent workspace BEFORE the sandbox boots. Parses .mcp.json, forge / agent-forge, Goose and Open Interpreter configurations plus every skill file, scores each item, and returns a boot / review |
| Continuous Attestation | Subscribe an MCP server, skill or live agent workspace to recurring re-scanning (default 7-day cycle). Detects drift against the recorded evidence hash, revokes certification when the score drops belo |
| Trust Score Lookup | Return an agent's AIShield Trust Score (0-100) and certification level from the Agent Registry. |
| Agent Identity & Credential Scan | Scan the agent identity layer (NHI). Verifies AgentCard / agent-identity declarations are signed (JWS/DID/proof), credentials are short-lived rather than never-expiring, authorization is least-privile |
| Agent Network / Mesh Config Scan | Scan the agent network layer. Flags Cloudflare Mesh / VPC bindings that expose the whole account network to every agent (the gap Cloudflare itself admits: 'per-agent identity and policy evaluation are |
| Attack Replay & Regression Detection | Snapshot and replay past attack payloads against the current rule set. Detects rule-regression: a payload that was previously blocked but is now allowed because rules were weakened or a pattern was mi |
| Vertical-Domain Semantic Risk Scan | Domain-specific semantic risk screening for high-sensitivity verticals: finance (fraud inducement / unlicensed wealth management / pump-and-dump), medical (unlicensed diagnosis / false cure claims), a |
Watching this agent since 2026-08-26T06:07:19Z. Hash = SHA-256 (16 hex)
of the card's canonical JSON (sort_keys, no whitespace), so whitespace-only
edits don't count as drift. Feed:
api/a2a-drift.json.
| when (UTC) | what | version | skills | hash was | hash now |
|---|---|---|---|---|---|
| 2026-08-29T00:39:52Z | changed | 4.2.0→4.3.0 | 5→11 | ec4c2c7214 | 1201053796 |
Endpoints on this host that also appear in the official MCP registry, with their live trust grades — one host, two protocols, measured independently.
| MCP endpoint | grade | MCP OK | auth |
|---|---|---|---|
| https://aishield.tools/api/v1/mcp | A | ✓ | open |
Golemreach Trust Layer · A2A index · method & opt-out · card re-fetched every sweep round; opt-out per /trust/bot removes the whole host within 48h.