KYA™ · Know Your Agent

Agent Trust Registry

Public registry of preliminary KYA™ signals for source-visible agent projects.
Scores support due diligence and capability controls. They are not final security certifications.

30
Agents tracked
30
Preliminary scans
2362
Findings flagged
1235
CVEs detected
Static analysis + OSV.dev CVE scan + NVIDIA Llama 70B audit · Questions? [email protected]
Tiers
Sovereign ≥85
Partner ≥72
Node ≥58
Rejected <58
Blended score: 30% manual baseline + 70% live analysis
Audit Methodology

How we score agents

Every score in this registry is produced by a three-stage preliminary pipeline run against a prioritized sample of the agent's public source code — no installs, no clones, no marketing materials. We inspect capabilities, check dependencies, and run an independent AI review.

Scores are a blend of our manual safety baseline (30%) and the live analysis result (70%). The baseline captures things code can't show: organizational maturity, incident history, and published safety disclosures. The live analysis reflects what's actually in the codebase today.

On false positives. Static analysis is inherently noisy. A CLI tool using child_process looks the same as a malicious subprocess call. An agent that legitimately browses the web will flag network patterns. We surface these signals — we don't suppress them — because the operator needs to make that judgment for their context. Over time, our detection patterns improve as we build type-aware and context-aware rules. Treat scores as a starting point for due diligence, not a final verdict.

01

Static code analysis

Pattern-based scan across a prioritized source sample fetched via GitHub API — no disk writes, no execution. We flag capabilities such as shell execution, code evaluation, and network access for review. A capability signal is not, by itself, a confirmed vulnerability.

02

Dependency CVE scan

We parse package.json and requirements.txt files without installing anything. Each dependency is queried against OSV.dev — Google's open vulnerability database — using their batch API. CVSS ≥7.0 is flagged as High, 4.0–7.0 as Medium. We also flag unpinned version ranges (^, ~, *) as supply chain risk.

03

AI-powered semantic audit

Source files are passed to a large language model (Llama 3.1 70B via NVIDIA NIM) with a structured security prompt. The model looks for issues static patterns miss: unsafe prompt construction, missing input validation on tool calls, context leakage between sessions, and missing human-in-the-loop checkpoints. This stage catches behavioral risks, not just syntactic ones.

04

Score composition

Five dimensions are scored: Framework (design-level guardrails), Code Health (quality and safety of implementation), Tool Permissions (blast radius of tool access), Prompt Safety (injection resistance), and Loop Safety (termination guarantees). These combine into a raw score, which is then blended with our manual baseline. Scores are re-run periodically as frameworks evolve.

General Open Source
79
IronClaw
Near AI
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:10
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
37 deps scanned via OSV.dev
60/525 prioritized files · 95bd515
Code Source Available
78
Claude Code
Anthropic
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:80
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
20/26 prioritized files · dd79613
General Open Source
78
Moltis
Moltis Org
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
M:3 I:26
Prompt SafetyTool Abuse Risk
23 deps scanned via OSV.dev
60/283 prioritized files · 678d407
Code Open Source
77
OpenHands
All Hands AI
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:23 CVE:1
Dependency VulnerabilityTool Abuse RiskPrompt Safety
Top finding ████████████████████████████████████ — classified
96 deps scanned via OSV.dev
60/839 prioritized files · 565c10d
General Open Source
76
UI-TARS
ByteDance
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:1 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
4/5 prioritized files · 582f3a7
General Open Source
74
OpenClaw
OpenClaw Labs
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:1
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
63 deps scanned via OSV.dev
60/24903 prioritized files · aa07d55
General Open Source
73
ZeroClaw
ZeroClaw Labs
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:48
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
27 deps scanned via OSV.dev
60/82 prioritized files · 7151551
Multi-Agent Open Source
72
LangGraph
LangChain Inc.
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
20 deps scanned via OSV.dev
60/462 prioritized files · b2926a0
General Open Source
72
PicoClaw
Sipeed
Partner Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
50 deps scanned via OSV.dev
60/64 prioritized files · 49183d7
General Open Source
71
LangChain Agent
LangChain Inc.
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:3 I:1
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
60/2538 prioritized files · 6dcdb63
Multi-Agent Open Source
68
AutoGen
Microsoft Research
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:1 M:6 I:9 CVE:4
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
38 deps scanned via OSV.dev
60/593 prioritized files · 027ecf0
Multi-Agent Open Source
66
CrewAI
CrewAI Inc.
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:4 I:34
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
60/1289 prioritized files · 7accafb
General Open Source
64
PydanticAI
Pydantic
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:3 M:3 I:4
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
50/622 prioritized files · c8bcbb1
Multi-Agent Open Source
62
OpenAI Swarm
OpenAI
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:4 M:3 I:4
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
55/63 prioritized files · 6af0b4c
General Open Source
59
OpenFang
RightNow AI
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:1 M:23 I:392 CVE:21
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
9 deps scanned via OSV.dev
36/39 prioritized files · acf2587
General Open Source
58
LlamaIndex
LlamaIndex Inc.
Node Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:1 M:18 I:1 CVE:16
Dependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████ — classified
17 deps scanned via OSV.dev
60/3963 prioritized files · 5c0e64e
General Open Source
56
Semantic Kernel
Microsoft
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:90 I:11 CVE:89
Loop SafetyDependency VulnerabilityPrompt Safety
Top finding ████████████████████████████████████ — classified
34 deps scanned via OSV.dev
60/1270 prioritized files · 383d102
General Open Source
55
Mastra
Mastra AI
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:57 I:52 CVE:55
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
157 deps scanned via OSV.dev
60/7937 prioritized files · c17c2f3
General Open Source
55
Agno
Agno (ex-Phidata)
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:374 I:2 CVE:372
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
328 deps scanned via OSV.dev
60/4305 prioritized files · 2e77399
Multi-Agent Open Source
55
Paperclip
PaperclipAI
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:16 I:42 CVE:14
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
108 deps scanned via OSV.dev
60/2360 prioritized files · 678728f
General Open Source
55
UI-TARS Desktop
ByteDance
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:191 I:63 CVE:189
Dependency VulnerabilityTool Abuse RiskPrompt Safety
Top finding ████████████████████████████████████ — classified
376 deps scanned via OSV.dev
60/1252 prioritized files · c2ad42e
General Open Source
55
Cherry Studio
CherryHQ
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:64 I:14 CVE:62
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
411 deps scanned via OSV.dev
60/3931 prioritized files · 9f21273
General Open Source
52
Hermes Agent
NousResearch
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:13 I:12 CVE:11
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
155 deps scanned via OSV.dev
43/5209 prioritized files · 4371712
General Open Source
49
Strands Agents
AWS / Strands
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:4 M:7 I:23 CVE:5
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
125 deps scanned via OSV.dev
60/1337 prioritized files · ad3e6fe
Research Open Source
49
Dexter
virattt
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:3 M:17 I:13 CVE:15
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
35 deps scanned via OSV.dev
60/218 prioritized files · ecaed30
Multi-Agent Open Source
47
MetaGPT
FoundationAgents
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:3 M:130 I:13 CVE:128
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
97 deps scanned via OSV.dev
60/919 prioritized files · 11cdf46
Multi-Agent Open Source
47
Agency Swarm
VRSEN
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:30 I:12 CVE:28
Loop SafetyDependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████ — classified
22 deps scanned via OSV.dev
60/401 prioritized files · 4d1c35a
General Open Source
46
AutoGPT
Significant Gravitas
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:2 M:27 I:20 CVE:22
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
151 deps scanned via OSV.dev
21/2218 prioritized files · c45b9e3
General Open Source
45
smolagents
Hugging Face
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:3 M:186 I:34 CVE:182
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
26 deps scanned via OSV.dev
27/77 prioritized files · e3a5b89
General Open Source
35
Nanobot
HKUDS
Rejected Preliminary scan Aug 4, 2026 Static refresh · AI findings preserved
H:5 M:24 I:35 CVE:21
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████ — classified
47 deps scanned via OSV.dev
27/734 prioritized files · be5af01

Apply for a KYA™ evaluation.

Approved capabilities depend on your agent, operator, jurisdiction, cohort, and licensed infrastructure partners. A preliminary registry score does not guarantee financial access.

Get Quick Sell token