Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
57
A2A v2.2.0

AgentScore

agentscores.xyz

MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain agentscores.xyz via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
1 thing in this card we could not use
Everything else was indexed. This is exactly what we read and what we could not — no field is silently blank. Fix the card at https://agentscores.xyz/.well-known/agent.json and the next probe clears this panel.
Field What we saw What we stored
capabilities Input should be a valid dictionary or instance of Capabilities dropped — this field was not indexed
Trust score
24/100
grade F · 9 criteria
Uptime
accumulating
1/5 direct probes · 30d
~1375 ms response
Observed inflow · 30d
—
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
1 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 24/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
partial Valid AgentCard 9/10
AgentCard did not read cleanly: 1 field we could not read. Scored on what we could read, not on a card that arrived as published — the card findings name every affected field and what we did with it.
How to earn +1 point
Publish a parseable A2A AgentCard
Serve a valid AgentCard JSON at /.well-known/agent-card.json. The A2A 1.0 schema is the reference; we accept the v0.x backwards-compatible variant too.
Docs →
fail Live JSON-RPC 5/25
Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response.
How to earn +20 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` (Major.Minor, no patch number — §3.6) to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 1 probe so far, need ≥5 for an uptime grade.
partial Skill declaration 6/10
Declares 1 skill, usable but thin.
How to earn +4 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags` — `description` and `tags` are REQUIRED on AgentSkill since A2A v1.0, and tags are what discovery filters match on. We canonicalise these into the global skill taxonomy on next probe.
Docs →
fail Verified Identity 0/10
No provider organisation declared. Anonymous agent.
How to earn +10 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-10-02 11:36:10 current fb4d576ff1d5… view →
Uptime
accumulating
1 direct probes · 30d
Response
270ms
last direct probe
Skills
0
declared
Streaming
—
SSE-capable

Endpoints

Agent cardhttps://agentscores.xyz/.well-known/agent.json
Discovered via
smithery

Skills · 1 declared · mapped to canonical taxonomy

AgentScore

MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.

canonical Agent Profiles match 85%

Health · last 1 probes

When HTTP Live JSON-RPC Latency
2026-10-02 11:36:10 200 ✗ 270ms

Cheaper or better alternatives per-skill

↑ 1 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

agentspec-one.vercel.app
Return a compact agent-readiness score for OpenAPI or MCP input.
agentspec-one.vercel.app · q 65%
AgentStamp
The identity, registry, and wishing well for AI agents. Reputation scores, cross-protocol passports, and live MCP discovery.
q 53%
AgentScore
AgentScore · q 85%
AgentTrust
Trust infrastructure for AI agents. Look up a registered agent by the exact URL you are about to call and receive its reliability score, end
q 76%
AgentTrust
Trust infrastructure for AI agents. Look up a registered agent by the exact URL you are about to call and receive its reliability score, end
q 76%
agentproof-murex.vercel.app
API contract score for agents - measure response stability before automation.
agentproof-murex.vercel.app · q 65%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/agentscores.xyz.svg)](https://agenstry.com/agents/agentscores.xyz)
[![Verified Business](https://agenstry.com/badge/agentscores.xyz/identity.svg)](https://agenstry.com/agents/agentscores.xyz)
[![Uptime](https://agenstry.com/badge/agentscores.xyz/uptime.svg)](https://agenstry.com/agents/agentscores.xyz)
[![A2A version](https://agenstry.com/badge/agentscores.xyz/protocol.svg)](https://agenstry.com/agents/agentscores.xyz)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "AgentScore",
  "description": "MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.",
  "url": "https://agentscores.xyz",
  "version": "2.2.0",
  "capabilities": [
    "mcp-scanning",
    "trust-verdict",
    "exposure-mapping",
    "monitoring",
    "advisories"
  ],
  "endpoints": {
    "scan": {
      "url": "https://agentscores.xyz/api/scan?npm={packageName}",
      "method": "GET",
      "description": "Scan any npm package for MCP security issues"
    },
    "verdict": {
      "url": "https://agentscores.xyz/api/verdict?npm={packageName}",
      "method": "GET",
      "description": "Trust verdict: allow, warn, or block"
    },
    "exposure": {
      "url": "https://agentscores.xyz/api/exposure?npm={packageName}",
      "method": "GET",
      "description": "Which monitored MCP servers depend on this package"
    },
    "advisories": {
      "url": "https://agentscores.xyz/api/advisories",
      "method": "GET",
      "description": "Security advisories feed"
    },
    "monitor": {
      "url": "https://agentscores.xyz/api/monitor?npm={packageName}",
      "method": "GET",
      "description": "Monitoring status and scan history"
    }
  },
  "mcp_server": {
    "npm": "@agentscore-xyz/mcp-server",
    "transport": "stdio",
    "tools": [
      "scan_package",
      "get_verdict",
      "check_exposure",
      "check_abuse",
      "monitor_status"
    ]
  }
}