AgentAvow Trust
Signed, offline-verifiable safety scores for the MCP servers, packages & tools an agent connects to
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"agentavow-trust": {
"command": "uvx",
"args": [
"agentavow-trust"
]
}
}
}Paquetes ejecutables
0.6.1stdioPuntos de conexión remotos
https://agentavow.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (8)
🟢scan_repo(repo, owner, force)
Scan a public GitHub repository with AgentAvow and return whether it is safe for an agent to connect to: a 0-100 trust score, a plain safe / needs-review verdict, the findings behind it (with where and how to fix), and a signed, offline-verifiable attestation. Read-only, no account. Calls the AgentAvow public API at agentavow.com.
Esquema de entrada
{
"type": "object",
"properties": {
"repo": {
"type": "string",
"description": "Repo as 'owner/name' (e.g. 'vercel/next.js'), or just the name when 'owner' is given separately.",
"maxLength": 214
},
"owner": {
"type": "string",
"description": "Repo owner (optional if 'repo' is already 'owner/name').",
"maxLength": 214
},
"force": {
"type": "boolean",
"description": "Re-scan now instead of returning the cached verdict (results cache ~1h). Use after the target has changed."
}
},
"required": [
"repo"
]
}🟢scan_package(registry, surface, ecosystem, name, force)
Scan a published package (npm, PyPI, crates, Docker, or Hugging Face) with AgentAvow. Returns a 0-100 trust score, a safe / needs-review verdict, findings with remediation, and a signed attestation. Also reports repo-vs-artifact drift (files shipped that aren't in the source). Read-only; calls agentavow.com.
Esquema de entrada
{
"type": "object",
"properties": {
"registry": {
"type": "string",
"description": "Package registry: npm, pypi, crates, docker, or hf."
},
"surface": {
"type": "string",
"description": "Alias for registry."
},
"ecosystem": {
"type": "string",
"description": "Alias for registry."
},
"name": {
"type": "string",
"description": "Package name, e.g. 'chalk' (or 'org/model' for hf).",
"maxLength": 214
},
"force": {
"type": "boolean",
"description": "Re-scan now instead of returning the cached verdict (results cache ~1h). Use after a new version ships."
}
},
"required": [
"name"
]
}🟢scan_mcp_server(endpoint_url, force)
Scan a live MCP server's tool definitions for tool-poisoning, prompt-injection, invisible-unicode, and manifest-execution risks before your agent connects to it. Returns a 0-100 trust score, a safe / needs-review verdict, findings, and a signed attestation. Read-only; calls the agentavow.com public API.
Esquema de entrada
{
"type": "object",
"properties": {
"endpoint_url": {
"type": "string",
"description": "The MCP server's https:// URL.",
"maxLength": 512
},
"force": {
"type": "boolean",
"description": "Re-scan now instead of returning the cached verdict (results cache ~1h)."
}
},
"required": [
"endpoint_url"
]
}🟢verify_trust(entity_id, min_trust)
Verify an AgentAvow entity's trust score. Returns trust_score (0-1), trust_score_pct (0-100), trust_tier, and whether it meets a minimum threshold. Read-only, no auth. Use before interacting with an unknown agent.
Esquema de entrada
{
"type": "object",
"properties": {
"entity_id": {
"type": "string",
"description": "UUID of a registered AgentAvow entity (resolve one with lookup_identity; unknown ids return guidance, not an error).",
"maxLength": 64
},
"min_trust": {
"type": "number",
"description": "Min score, 0-1.",
"default": 0.3
}
},
"required": [
"entity_id"
]
}🟢check_interaction_safety(target_entity_id, interaction_type)
Check whether it is safe to interact with another agent by trust threshold. Thresholds: delegate 0.6, trade 0.5, collaborate 0.4, follow 0.1. Returns is_safe, risk_level, the score, and a recommendation. Read-only, no auth.
Esquema de entrada
{
"type": "object",
"properties": {
"target_entity_id": {
"type": "string",
"description": "UUID of a registered target entity (resolve one with lookup_identity).",
"maxLength": 64
},
"interaction_type": {
"type": "string",
"enum": [
"delegate",
"trade",
"collaborate",
"follow"
]
}
},
"required": [
"target_entity_id",
"interaction_type"
]
}🟢lookup_identity(query)
Look up an AgentAvow entity by W3C DID or display name. Returns the entity's id, name, type, trust score and tier. Read-only, no auth. Use to resolve an identity before checking its trust.
Esquema de entrada
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "A did:web:... or a display name.",
"maxLength": 200,
"pattern": "^[\\w .:/@#+-]{1,200}$"
}
},
"required": [
"query"
]
}🟢get_trust_badge(entity_id)
Get an embeddable AgentAvow trust badge (SVG) for an entity, with ready-to-paste Markdown and HTML. The badge auto-updates as the score changes. Read-only, no auth.
Esquema de entrada
{
"type": "object",
"properties": {
"entity_id": {
"type": "string",
"description": "UUID of a registered AgentAvow entity (resolve one with lookup_identity).",
"maxLength": 64
}
},
"required": [
"entity_id"
]
}🟢about_agentavow
What AgentAvow is, which tool to use for what, how to read a verdict, and example scans. Call this for an overview or when getting started. No input, read-only.
Esquema de entrada
{
"type": "object",
"properties": {}
}Comunidad
Evidencia