← all agents · MCP trust index
AI-powered code quality guardian. Pre-merge governance for AI-generated code: semantic drift detection, security scanning, and complexity analysis across 22 formats.
Everything on this page was fetched from the agent's own well-known card by GolemreachTrustBot (outside-in probe, last checked 2026-08-29T17:21:46Z, first seen 2026-08-26T05:57:03Z). Not self-submitted, not cached from a directory.
| field | value |
|---|---|
| A2A endpoint | https://hefestoai.narapallc.com |
| card source | https://hefestoai.narapallc.com/.well-known/agent-card.json |
| protocolVersion | — |
| agent version | 4.13.1 |
| preferredTransport | — |
| provider | Narapa LLC |
| skills published | 3 |
| card hash (canonical) | 2f41345d7aace6ad |
| transport | URL |
|---|---|
| unspecified | https://hefestoai.narapallc.com |
| skill | description |
|---|---|
| Code Analysis | Analyze code files or directories for security vulnerabilities, complexity issues, semantic drift, and code smells. Supports Python, TypeScript, JavaScript, Java, Go, Rust, C#, plus 15 DevOps and Clou |
| Security Scanning | Detect HARDCODED_SECRET, SQL_INJECTION, COMMAND_INJECTION, PATH_TRAVERSAL, UNSAFE_DESERIALIZATION and other security vulnerabilities. |
| Semantic Drift Detection | Detect when AI-generated code deviates from intended behavior. Validates that code does what the prompt asked for. |
Watching this agent since 2026-08-26T05:57:03Z. Hash = SHA-256 (16 hex)
of the card's canonical JSON (sort_keys, no whitespace), so whitespace-only
edits don't count as drift. Feed:
api/a2a-drift.json.
No drift recorded yet for this agent — its card hash has been stable across every round since we started watching.
Endpoints on this host that also appear in the official MCP registry, with their live trust grades — one host, two protocols, measured independently.
| MCP endpoint | grade | MCP OK | auth |
|---|---|---|---|
| https://hefestoai.narapallc.com/api/mcp-protocol | A | ✓ | open |
Golemreach Trust Layer · A2A index · method & opt-out · card re-fetched every sweep round; opt-out per /trust/bot removes the whole host within 48h.