AgentScore
agentscores.xyz
MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.
agentscores.xyz via a single DNS TXT record to add the
verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
https://agentscores.xyz/.well-known/agent.json and the next probe clears this panel.
| Field | What we saw | What we stored |
|---|---|---|
capabilities |
Input should be a valid dictionary or instance of Capabilities | dropped — this field was not indexed |
Dispute or improve this rating
F
Conformance score: 24/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾
click to collapse breakdown ▴
agent-card.json changed within the last 7 days. We track these so downstream callers can react.
Activity (audit trail)
last 24h · 0 invocations Public aggregate · no PII recordedNothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.
Card history
1 snapshot Every change toagent-card.json
| Captured | Hash | |
|---|---|---|
| 2026-10-02 11:36:10 current | fb4d576ff1d5… |
view → |
Skills · 1 declared · mapped to canonical taxonomy
MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.
Health · last 1 probes
Cheaper or better alternatives per-skill
For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.
Similar agents embedding-nearest
Embed your Agenstry badge
Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.
Markdown / HTML snippets
[](https://agenstry.com/agents/agentscores.xyz) [](https://agenstry.com/agents/agentscores.xyz) [](https://agenstry.com/agents/agentscores.xyz) [](https://agenstry.com/agents/agentscores.xyz)
Audit-grade evidence bundle
JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against
our JWKS. See the methodology.
Raw agent card JSON
{
"name": "AgentScore",
"description": "MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuously.",
"url": "https://agentscores.xyz",
"version": "2.2.0",
"capabilities": [
"mcp-scanning",
"trust-verdict",
"exposure-mapping",
"monitoring",
"advisories"
],
"endpoints": {
"scan": {
"url": "https://agentscores.xyz/api/scan?npm={packageName}",
"method": "GET",
"description": "Scan any npm package for MCP security issues"
},
"verdict": {
"url": "https://agentscores.xyz/api/verdict?npm={packageName}",
"method": "GET",
"description": "Trust verdict: allow, warn, or block"
},
"exposure": {
"url": "https://agentscores.xyz/api/exposure?npm={packageName}",
"method": "GET",
"description": "Which monitored MCP servers depend on this package"
},
"advisories": {
"url": "https://agentscores.xyz/api/advisories",
"method": "GET",
"description": "Security advisories feed"
},
"monitor": {
"url": "https://agentscores.xyz/api/monitor?npm={packageName}",
"method": "GET",
"description": "Monitoring status and scan history"
}
},
"mcp_server": {
"npm": "@agentscore-xyz/mcp-server",
"transport": "stdio",
"tools": [
"scan_package",
"get_verdict",
"check_exposure",
"check_abuse",
"monitor_status"
]
}
}