KYA™ · Know Your Agent

Agent Trust Registry

Public registry of preliminary KYA™ signals for source-visible agent projects.
Scores support due diligence and capability controls. They are not final security certifications.

30
Agents tracked
30
Preliminary scans
2806
Findings flagged
1710
CVEs detected
Static analysis + OSV.dev CVE scan + NVIDIA Llama 70B audit · Questions? [email protected]
Tiers
Sovereign ≥85
Partner ≥75
Node ≥60
Rejected <58
Blended score: 30% manual baseline + 70% live analysis
Audit Methodology

How we score agents

Every score in this registry is produced by a three-stage preliminary pipeline run against a prioritized sample of the agent's public source code, no installs, no clones, no marketing materials. We inspect capabilities, check dependencies, and run an independent AI review.

Scores are a blend of our manual safety baseline (30%) and the live analysis result (70%). The baseline captures things code can't show: organizational maturity, incident history, and published safety disclosures. The live analysis reflects what's actually in the codebase today.

On false positives. Static analysis is inherently noisy. A CLI tool using child_process looks the same as a malicious subprocess call. An agent that legitimately browses the web will flag network patterns. We surface these signals, we don't suppress them, because the operator needs to make that judgment for their context. Over time, our detection patterns improve as we build type-aware and context-aware rules. Treat scores as a starting point for due diligence, not a final verdict.

01

Static code analysis

Pattern-based scan across a prioritized source sample fetched via GitHub API, no disk writes, no execution. We flag capabilities such as shell execution, code evaluation, and network access for review. A capability signal is not, by itself, a confirmed vulnerability.

02

Dependency CVE scan

We parse package.json and requirements.txt files without installing anything. Each dependency is queried against OSV.dev, Google's open vulnerability database, using their batch API. CVSS ≥7.0 is flagged as High, 4.0-7.0 as Medium. We also flag unpinned version ranges (^, ~, *) as supply chain risk.

03

AI-powered semantic audit

Source files are passed to a large language model (Llama 3.1 70B via NVIDIA NIM) with a structured security prompt. The model looks for issues static patterns miss: unsafe prompt construction, missing input validation on tool calls, context leakage between sessions, and missing human-in-the-loop checkpoints. This stage catches behavioral risks, not just syntactic ones.

04

Score composition

Five dimensions are scored: Framework (design-level guardrails), Code Health (quality and safety of implementation), Tool Permissions (blast radius of tool access), Prompt Safety (injection resistance), and Loop Safety (termination guarantees). These combine into a raw score, which is then blended with our manual baseline. Scores are re-run periodically as frameworks evolve.

Code Source Available
79
Claude Code
Anthropic
Partner Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:3 I:1
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
60/1282 prioritized files · 2bfb629
General Open Source
78
UI-TARS
ByteDance
Partner Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:2 I:6
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
4/5 prioritized files · 582f3a7
General Open Source
76
LangChain Agent
LangChain Inc.
Partner Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:2 I:2
Prompt Safety
Top finding ████████████████████████████████████, classified
60/2617 prioritized files · 007cc15
Multi-Agent Open Source
76
LangGraph
LangChain Inc.
Partner Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
27 deps scanned via OSV.dev
60/477 prioritized files · 9a0394d
General Open Source
76
ZeroClaw
ZeroClaw Labs
Partner Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:2 I:104
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
30 deps scanned via OSV.dev
40/142 prioritized files · 19c40ee
General Open Source
73
Moltis
Moltis Org
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:3 I:27
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
23 deps scanned via OSV.dev
60/295 prioritized files · 1f6d28e
General Open Source
72
IronClaw
Near AI
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:4 I:11 CVE:2
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
49 deps scanned via OSV.dev
53/607 prioritized files · b0b999d
General Open Source
72
PicoClaw
Sipeed
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
50 deps scanned via OSV.dev
60/64 prioritized files · bbf6893
Multi-Agent Open Source
71
CrewAI
CrewAI Inc.
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:3 I:38
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
60/1399 prioritized files · 738c8e1
General Open Source
69
OpenClaw
OpenClaw Labs
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:4 I:2 CVE:2
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
69 deps scanned via OSV.dev
60/43688 prioritized files · 689bda0
General Open Source
65
PydanticAI
Pydantic
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:3 M:3 I:3
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
48/1709 prioritized files · 721c78d
Multi-Agent Open Source
64
AutoGen
Microsoft Research
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:6 I:9 CVE:4
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
38 deps scanned via OSV.dev
60/593 prioritized files · 027ecf0
Multi-Agent Open Source
62
OpenAI Swarm
OpenAI
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:4 M:3 I:5
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
55/63 prioritized files · 6af0b4c
General Open Source
60
Agno
Agno (ex-Phidata)
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:566 I:1 CVE:564
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
345 deps scanned via OSV.dev
60/5039 prioritized files · c44b082
Code Open Source
60
OpenHands
All Hands AI
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:18 I:9 CVE:16
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
98 deps scanned via OSV.dev
36/1063 prioritized files · 64f12b3
General Open Source
60
UI-TARS Desktop
ByteDance
Node Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:234 I:63 CVE:232
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
377 deps scanned via OSV.dev
60/1263 prioritized files · 2ff41a9
General Open Source
56
LlamaIndex
LlamaIndex Inc.
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:143 I:1 CVE:140
Dependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████, classified
217 deps scanned via OSV.dev
60/3885 prioritized files · 962940d
General Open Source
56
Semantic Kernel
Microsoft
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:94 I:11 CVE:93
Loop SafetyDependency VulnerabilityPrompt Safety
Top finding ████████████████████████████████████, classified
33 deps scanned via OSV.dev
60/1275 prioritized files · 9974625
General Open Source
55
AutoGPT
Significant Gravitas
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:21 I:24 CVE:19
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
142 deps scanned via OSV.dev
22/3681 prioritized files · f8b0e0a
General Open Source
55
Hermes Agent
NousResearch
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:24 I:11 CVE:22
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
172 deps scanned via OSV.dev
47/11086 prioritized files · 61f8365
General Open Source
55
OpenFang
RightNow AI
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:23 I:392 CVE:21
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
9 deps scanned via OSV.dev
36/39 prioritized files · acf2587
General Open Source
55
Cherry Studio
CherryHQ
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:97 I:15 CVE:95
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
531 deps scanned via OSV.dev
44/5399 prioritized files · 50d69b6
General Open Source
54
Mastra
Mastra AI
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:17 I:56 CVE:15
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
177 deps scanned via OSV.dev
60/12451 prioritized files · 329ff3f
Multi-Agent Open Source
54
Paperclip
PaperclipAI
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:2 M:21 I:46 CVE:18
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
144 deps scanned via OSV.dev
60/4742 prioritized files · 1c07b59
Multi-Agent Open Source
53
Agency Swarm
VRSEN
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:1 M:32 I:12 CVE:30
Dependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████, classified
22 deps scanned via OSV.dev
60/431 prioritized files · 1aeb325
Research Open Source
49
Dexter
virattt
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:3 M:29 I:12 CVE:27
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
35 deps scanned via OSV.dev
60/218 prioritized files · 534f6be
General Open Source
48
smolagents
Hugging Face
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:3 M:216 I:35 CVE:214
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
26 deps scanned via OSV.dev
27/77 prioritized files · c30b115
General Open Source
47
Strands Agents
AWS / Strands
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:3 M:10 I:37 CVE:7
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
157 deps scanned via OSV.dev
60/1947 prioritized files · 59f126f
Multi-Agent Open Source
47
MetaGPT
FoundationAgents
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:3 M:169 I:13 CVE:167
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
97 deps scanned via OSV.dev
60/919 prioritized files · 11cdf46
General Open Source
45
Nanobot
HKUDS
Rejected Preliminary scan Oct 5, 2026 Static refresh · AI findings preserved
H:4 M:24 I:17 CVE:22
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
56 deps scanned via OSV.dev
30/1087 prioritized files · 6ff96f2

Apply for a KYA™ evaluation.

Approved capabilities depend on your agent, operator, jurisdiction, cohort, and licensed infrastructure partners. A preliminary registry score does not guarantee financial access.

Get Quick Sell token