Card snapshot
backbond.ai
·
2026-10-10 01:57:17 UTC
·
b470e0ad03b1fe1d99e7c42bac1611167e560cdfbc68618b9607b746f5532305
This is a frozen copy of the agent's agent-card.json as we observed it at the timestamp above. We capture a new snapshot every time the card's content hash changes. Useful for: forensic drift analysis, verifying downstream callers see the right version, reproducing routing decisions made historically.
{
"$comment": "Public discovery card. This endpoint does not execute scans or receive scan inputs.",
"name": "BackBond Agent Scan",
"description": "Vet MCP and AI-agent tool metadata locally before attachment.",
"url": "https://backbond.ai/agent-scan/",
"provider": {
"organization": "BackBond",
"url": "https://backbond.ai/"
},
"version": "0.6.3",
"documentationUrl": "https://github.com/BackBond/agent-scan",
"agentInstructionsUrl": "https://backbond.ai/agent-scan/agents/",
"hostIntegrationUrl": "https://backbond.ai/agent-scan/agents/",
"rulesUrl": "https://backbond.ai/agent-scan/rules/",
"hostGate": {
"status": "awaiting-compatible-release",
"publishedVersion": "0.1.0",
"scannerVersion": "0.6.2",
"compatibleWithCurrentScanner": false,
"reason": "The published gate embeds the 0.6.2 scanner digest and rejects 0.6.3. Installation instructions are withdrawn pending a compatible release. Do not bypass digest verification."
},
"registryIdentity": "io.github.BackBond/agent-scan",
"commands": {
"vetBeforeAttach": "npx -y @backbond/agent-scan@0.6.3 vet-tools --stdin < tools-list.json",
"discoveryScan": "npx -y @backbond/agent-scan@0.6.3 scan",
"scanSuppliedTools": "npx -y @backbond/agent-scan@0.6.3 scan --stdin --require-coverage < tools-list.json",
"committedManifestGate": "BackBond/agent-scan@v0.6.3 with mode: vet-tools and tool-schema: tools-list.json",
"installAgentSkill": "npx -y skills@1.5.18 add https://github.com/BackBond/agent-scan/tree/v0.6.3 --skill agent-scan --yes"
},
"outcomes": {
"0": "no_blocking_finding: no configured blocking rule fired on the supplied static metadata",
"1": "block: the scanner completed and a blocking rule fired",
"2": "invalid input or scanner failure",
"3": "review: the scanner completed but evidence was incomplete or ambiguous"
},
"boundaries": {
"discovery": "The no-argument scan uses bounded local discovery and may not see live MCP tools. Missing live tool lists are a coverage gap, not a complete agent scan.",
"hostStatus": "Some IDEs label every non-zero process exit as failed. Exit 1 and exit 3 remain completed scanner decisions.",
"network": "npx may contact npm to download the pinned package. Once running, the scanner does not upload scan inputs or contact a hosted analysis service."
},
"voluntaryRunReport": {
"url": "https://github.com/BackBond/agent-scan/issues/new?template=external-run.yml",
"fields": [
"pin started",
"decision",
"attach changed",
"OS / Node",
"sanitized false positive"
],
"privacy": "Do not submit raw manifests, prompts, traces, configurations, JSON reports, paths, tool names, secrets, people, or organizations."
},
"capabilities": {
"streaming": false,
"pushNotifications": false,
"executesThirdPartyTools": false,
"uploadsScanInputs": false
},
"skills": [
{
"id": "vet_tools_before_attach",
"name": "Vet tools before attaching them",
"description": "Return a scoped static block, review, or no-blocking-finding decision for a supplied tool manifest.",
"tags": [
"agent-security",
"pre-attachment",
"mcp",
"static-analysis"
]
},
{
"id": "scan_agent_evidence",
"name": "Scan local agent evidence",
"description": "Run deterministic local rules over supplied or discovered tool metadata, permissions, and trace summaries.",
"tags": [
"agent-security",
"static-analysis",
"scan-record"
]
}
],
"securityPolicyUrl": "https://github.com/BackBond/agent-scan/blob/v0.6.3/SECURITY.md"
}