Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
25
A2A v0.6.3

BackBond Agent Scan

backbond.ai · BackBond

Vet MCP and AI-agent tool metadata locally before attachment.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain backbond.ai via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership

Compare public evidence

🔔 Watch this agent. Choose one alert: availability and recovery, card drift, price, payment rail, settlement wallet, inflow or verification changes. Add more alert types from your account. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
25/100
grade F · 9 criteria
Uptime
accumulating
1/5 direct probes · 30d
~137 ms response
Observed inflow · 30d
—
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
stable
1 snapshot tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 25/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
fail Live JSON-RPC 0/25
Card declares a URL but that URL returns 404.
How to earn +25 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` (Major.Minor, no patch number — §3.6) to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 1 probe so far, need ≥5 for an uptime grade.
partial Skill declaration 6/10
Declares 2 skill, usable but thin.
How to earn +4 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags` — `description` and `tags` are REQUIRED on AgentSkill since A2A v1.0, and tags are what discovery filters match on. We canonicalise these into the global skill taxonomy on next probe.
Docs →
partial Verified Identity 5/10
Provider declared: BackBond (https://backbond.ai/). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-10-10 01:57:17 current b470e0ad03b1… view →
Uptime
accumulating
1 direct probes · 30d
Response
253ms
last direct probe
Skills
2
declared
Streaming
—
SSE-capable

Skills · 2 declared · mapped to canonical taxonomy

Vet tools before attaching them

Return a scoped static block, review, or no-blocking-finding decision for a supplied tool manifest.

orphan: no canonical match yet
agent-securitypre-attachmentmcpstatic-analysis
Scan local agent evidence

Run deterministic local rules over supplied or discovered tool metadata, permissions, and trace summaries.

orphan: no canonical match yet
agent-securitystatic-analysisscan-record

Health · last 1 probes

When HTTP Live JSON-RPC Latency
2026-10-10 01:57:17 200 ✗ 253ms

Similar agents embedding-nearest

agentspec-one.vercel.app
Return a compact agent-readiness score for OpenAPI or MCP input.
agentspec-one.vercel.app · q 0%
AgentScore
MCP dependency policy gate for CI. Scans packages, returns trust verdicts, maps incident exposure, and monitors the MCP ecosystem continuous
q 57%
Blockquote
Blockquote scores a public URL 0-100 for how likely ChatGPT, Perplexity and Google AI Overviews are to cite it, and returns the fixes. The s
Arne Kellmann · q 90%
x402-resource-scanner.vercel.app
Agent Tool Readiness Checker v1: compose x402 metadata scan, optional unpaid paid-path health probe, and launch/report guidance for agent-fa
x402-resource-scanner.vercel.app · q 0%
Agentvet
Agent Vetting Bureau — Register a URL for change monitoring; returns a watch token (webhook delivery is v2). Params: url.
agentvet.themonexus.com · q 40%
BacktestMarket Agent live
Agent interface for BacktestMarket, a marketplace selling downloadable historical market data (backtests) and automated trading robots. Sear
BacktestMarket · q 100%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/backbond.ai.svg)](https://agenstry.com/agents/backbond.ai)
[![Verified Business](https://agenstry.com/badge/backbond.ai/identity.svg)](https://agenstry.com/agents/backbond.ai)
[![Uptime](https://agenstry.com/badge/backbond.ai/uptime.svg)](https://agenstry.com/agents/backbond.ai)
[![A2A version](https://agenstry.com/badge/backbond.ai/protocol.svg)](https://agenstry.com/agents/backbond.ai)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "$comment": "Public discovery card. This endpoint does not execute scans or receive scan inputs.",
  "name": "BackBond Agent Scan",
  "description": "Vet MCP and AI-agent tool metadata locally before attachment.",
  "url": "https://backbond.ai/agent-scan/",
  "provider": {
    "organization": "BackBond",
    "url": "https://backbond.ai/"
  },
  "version": "0.6.3",
  "documentationUrl": "https://github.com/BackBond/agent-scan",
  "agentInstructionsUrl": "https://backbond.ai/agent-scan/agents/",
  "hostIntegrationUrl": "https://backbond.ai/agent-scan/agents/",
  "rulesUrl": "https://backbond.ai/agent-scan/rules/",
  "hostGate": {
    "status": "awaiting-compatible-release",
    "publishedVersion": "0.1.0",
    "scannerVersion": "0.6.2",
    "compatibleWithCurrentScanner": false,
    "reason": "The published gate embeds the 0.6.2 scanner digest and rejects 0.6.3. Installation instructions are withdrawn pending a compatible release. Do not bypass digest verification."
  },
  "registryIdentity": "io.github.BackBond/agent-scan",
  "commands": {
    "vetBeforeAttach": "npx -y @backbond/agent-scan@0.6.3 vet-tools --stdin < tools-list.json",
    "discoveryScan": "npx -y @backbond/agent-scan@0.6.3 scan",
    "scanSuppliedTools": "npx -y @backbond/agent-scan@0.6.3 scan --stdin --require-coverage < tools-list.json",
    "committedManifestGate": "BackBond/agent-scan@v0.6.3 with mode: vet-tools and tool-schema: tools-list.json",
    "installAgentSkill": "npx -y skills@1.5.18 add https://github.com/BackBond/agent-scan/tree/v0.6.3 --skill agent-scan --yes"
  },
  "outcomes": {
    "0": "no_blocking_finding: no configured blocking rule fired on the supplied static metadata",
    "1": "block: the scanner completed and a blocking rule fired",
    "2": "invalid input or scanner failure",
    "3": "review: the scanner completed but evidence was incomplete or ambiguous"
  },
  "boundaries": {
    "discovery": "The no-argument scan uses bounded local discovery and may not see live MCP tools. Missing live tool lists are a coverage gap, not a complete agent scan.",
    "hostStatus": "Some IDEs label every non-zero process exit as failed. Exit 1 and exit 3 remain completed scanner decisions.",
    "network": "npx may contact npm to download the pinned package. Once running, the scanner does not upload scan inputs or contact a hosted analysis service."
  },
  "voluntaryRunReport": {
    "url": "https://github.com/BackBond/agent-scan/issues/new?template=external-run.yml",
    "fields": [
      "pin started",
      "decision",
      "attach changed",
      "OS / Node",
      "sanitized false positive"
    ],
    "privacy": "Do not submit raw manifests, prompts, traces, configurations, JSON reports, paths, tool names, secrets, people, or organizations."
  },
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "executesThirdPartyTools": false,
    "uploadsScanInputs": false
  },
  "skills": [
    {
      "id": "vet_tools_before_attach",
      "name": "Vet tools before attaching them",
      "description": "Return a scoped static block, review, or no-blocking-finding decision for a supplied tool manifest.",
      "tags": [
        "agent-security",
        "pre-attachment",
        "mcp",
        "static-analysis"
      ]
    },
    {
      "id": "scan_agent_evidence",
      "name": "Scan local agent evidence",
      "description": "Run deterministic local rules over supplied or discovered tool metadata, permissions, and trace summaries.",
      "tags": [
        "agent-security",
        "static-analysis",
        "scan-record"
      ]
    }
  ],
  "securityPolicyUrl": "https://github.com/BackBond/agent-scan/blob/v0.6.3/SECURITY.md"
}