AgentAvow Trust

Signed, offline-verifiable safety scores for the MCP servers, packages & tools an agent connects to

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
90%
命名品質
88%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,417Token(工具定義)
~864 B典型回應大小
中等的注意力影響(128k 上下文的 1.11%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "agentavow-trust": {
      "command": "uvx",
      "args": [
        "agentavow-trust"
      ]
    }
  }
}

可執行的套件

pypiagentavow-trust0.6.1stdio

遠端端點

https://agentavow.com/mcpstreamable-http

它能做什麼

工具清單

工具(8)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢scan_repo(repo, owner, force)

Scan a public GitHub repository with AgentAvow and return whether it is safe for an agent to connect to: a 0-100 trust score, a plain safe / needs-review verdict, the findings behind it (with where and how to fix), and a signed, offline-verifiable attestation. Read-only, no account. Calls the AgentAvow public API at agentavow.com.

輸入結構描述

{
  "type": "object",
  "properties": {
    "repo": {
      "type": "string",
      "description": "Repo as 'owner/name' (e.g. 'vercel/next.js'), or just the name when 'owner' is given separately.",
      "maxLength": 214
    },
    "owner": {
      "type": "string",
      "description": "Repo owner (optional if 'repo' is already 'owner/name').",
      "maxLength": 214
    },
    "force": {
      "type": "boolean",
      "description": "Re-scan now instead of returning the cached verdict (results cache ~1h). Use after the target has changed."
    }
  },
  "required": [
    "repo"
  ]
}
🟢scan_package(registry, surface, ecosystem, name, force)

Scan a published package (npm, PyPI, crates, Docker, or Hugging Face) with AgentAvow. Returns a 0-100 trust score, a safe / needs-review verdict, findings with remediation, and a signed attestation. Also reports repo-vs-artifact drift (files shipped that aren't in the source). Read-only; calls agentavow.com.

輸入結構描述

{
  "type": "object",
  "properties": {
    "registry": {
      "type": "string",
      "description": "Package registry: npm, pypi, crates, docker, or hf."
    },
    "surface": {
      "type": "string",
      "description": "Alias for registry."
    },
    "ecosystem": {
      "type": "string",
      "description": "Alias for registry."
    },
    "name": {
      "type": "string",
      "description": "Package name, e.g. 'chalk' (or 'org/model' for hf).",
      "maxLength": 214
    },
    "force": {
      "type": "boolean",
      "description": "Re-scan now instead of returning the cached verdict (results cache ~1h). Use after a new version ships."
    }
  },
  "required": [
    "name"
  ]
}
🟢scan_mcp_server(endpoint_url, force)

Scan a live MCP server's tool definitions for tool-poisoning, prompt-injection, invisible-unicode, and manifest-execution risks before your agent connects to it. Returns a 0-100 trust score, a safe / needs-review verdict, findings, and a signed attestation. Read-only; calls the agentavow.com public API.

輸入結構描述

{
  "type": "object",
  "properties": {
    "endpoint_url": {
      "type": "string",
      "description": "The MCP server's https:// URL.",
      "maxLength": 512
    },
    "force": {
      "type": "boolean",
      "description": "Re-scan now instead of returning the cached verdict (results cache ~1h)."
    }
  },
  "required": [
    "endpoint_url"
  ]
}
🟢verify_trust(entity_id, min_trust)

Verify an AgentAvow entity's trust score. Returns trust_score (0-1), trust_score_pct (0-100), trust_tier, and whether it meets a minimum threshold. Read-only, no auth. Use before interacting with an unknown agent.

輸入結構描述

{
  "type": "object",
  "properties": {
    "entity_id": {
      "type": "string",
      "description": "UUID of a registered AgentAvow entity (resolve one with lookup_identity; unknown ids return guidance, not an error).",
      "maxLength": 64
    },
    "min_trust": {
      "type": "number",
      "description": "Min score, 0-1.",
      "default": 0.3
    }
  },
  "required": [
    "entity_id"
  ]
}
🟢check_interaction_safety(target_entity_id, interaction_type)

Check whether it is safe to interact with another agent by trust threshold. Thresholds: delegate 0.6, trade 0.5, collaborate 0.4, follow 0.1. Returns is_safe, risk_level, the score, and a recommendation. Read-only, no auth.

輸入結構描述

{
  "type": "object",
  "properties": {
    "target_entity_id": {
      "type": "string",
      "description": "UUID of a registered target entity (resolve one with lookup_identity).",
      "maxLength": 64
    },
    "interaction_type": {
      "type": "string",
      "enum": [
        "delegate",
        "trade",
        "collaborate",
        "follow"
      ]
    }
  },
  "required": [
    "target_entity_id",
    "interaction_type"
  ]
}
🟢lookup_identity(query)

Look up an AgentAvow entity by W3C DID or display name. Returns the entity's id, name, type, trust score and tier. Read-only, no auth. Use to resolve an identity before checking its trust.

輸入結構描述

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "A did:web:... or a display name.",
      "maxLength": 200,
      "pattern": "^[\\w .:/@#+-]{1,200}$"
    }
  },
  "required": [
    "query"
  ]
}
🟢get_trust_badge(entity_id)

Get an embeddable AgentAvow trust badge (SVG) for an entity, with ready-to-paste Markdown and HTML. The badge auto-updates as the score changes. Read-only, no auth.

輸入結構描述

{
  "type": "object",
  "properties": {
    "entity_id": {
      "type": "string",
      "description": "UUID of a registered AgentAvow entity (resolve one with lookup_identity).",
      "maxLength": 64
    }
  },
  "required": [
    "entity_id"
  ]
}
🟢about_agentavow

What AgentAvow is, which tool to use for what, how to read a verdict, and example scans. Call this for an overview or when getting started. No input, read-only.

輸入結構描述

{
  "type": "object",
  "properties": {}
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本8 個工具
已驗證未記錄版本8 個工具