AIShield Security Scanner
This profile reflects information published by the agent provider.
Card passedProtocol response unconfirmedUnsigned card
About this agent
LocalMark's observation
LocalMark first listed this public Agent Card on 10 Oct 2026, 07:51 UTC. Its latest card check succeeded; the card declares 11 skills and a A2A interface. LocalMark has not run a task against this agent.
What LocalMark checked
- Published Agent Card
Inspect the source card ↗. The last successful fetch was 10 Oct 2026, 08:00 UTC.
- Latest card check: passed
10 Oct 2026, 08:00 UTC · Agent Card validated
- Advertised endpoint: TLS connection passed
10 Oct 2026, 08:00 UTC · Valid TLS connection to advertised endpoint host; no A2A request sent This does not test the A2A protocol or run a task.
- Read-only protocol probe: Protocol response unconfirmed
10 Oct 2026, 07:51 UTC · Advertised A2A task lookup method was not found LocalMark sent no message and did not request task creation.
- Unsigned card
This card does not provide a digital signature. Checked 10 Oct 2026, 08:00 UTC.
- 30-day card check history
2 of 2 recorded card checks passed in the last 30 days. These are periodic observations, not continuous uptime monitoring.
- Publisher claim
No publisher claim has been completed for this listing.
Card availability and a valid signature do not prove provider identity, task performance, or safety. LocalMark has not executed a task against this agent.
Recent card checks
Periodic observations over the last 30 days; they are not continuous uptime monitoring.
Show 2 recent checks
- Passed · 10 Oct 2026, 08:00 UTC
Agent Card validated
- Passed · 10 Oct 2026, 07:51 UTC
Agent Card validated
Card and signature changes
- No changes recorded since change tracking began.
Share this listing
Link to this profile with a status badge that updates from LocalMark checks.
README Markdown:
[](https://localmark.ai/agents/9282)Card-declared connections
These links come from statements in public Agent Cards. They do not verify common ownership or cooperation.
- No card-declared connections recorded yet.
Declared skills 11
- Agent Computer Pre-Flight Scan
Scan an agent workspace BEFORE the sandbox boots. Parses .mcp.json, forge / agent-forge, Goose and Open Interpreter configurations plus every skill file, scores each item, and returns a boot / review / refuse verdict. Complements isolation runtimes (Cloudflare Sandboxes and Containers, forgevm, E2B, Open Interpreter, Goose) which bound blast radius but do not inspect the content an agent loads inside the box. Also checks 11 sandbox-hardening rules on the box definition itself: mounted docker.sock, --privileged, host network/PID/IPC namespaces, cap_add ALL, CAP_SYS_ADMIN, seccomp=unconfined, --user 0, Kubernetes hostPath. PURELY STATIC: never spawns a command found in the workspace, never fetches the network.
- Agent Identity & Credential Scan
Scan the agent identity layer (NHI). Verifies AgentCard / agent-identity declarations are signed (JWS/DID/proof), credentials are short-lived rather than never-expiring, authorization is least-privilege (flags scope:'*' and over-broad grants that violate scope attenuation), and mTLS/DID verification is present. This is the fastest-moving front of 2026 agent security (the top A2A issues are all identity; Authentik's NHI wave; ANS/DNSid/Entra Agent ID). AIShield both issues trust certificates AND audits identity defects.
- Agent Network / Mesh Config Scan
Scan the agent network layer. Flags Cloudflare Mesh / VPC bindings that expose the whole account network to every agent (the gap Cloudflare itself admits: 'per-agent identity and policy evaluation are future work'), unauthenticated agent endpoints (auth: none), bind-to-all-interfaces exposure (0.0.0.0), and private/internal resources marked public:true. Answers the 'trust shallow' problem left open by A2A's signed AgentCard: content trust + identity attribution + network reachability.
- Agentic AI Audit
Audit an AI agent against OWASP Agentic AI Top 10 (ASI01-ASI10): goal hijack, tool misuse, identity abuse, supply chain, code execution, memory poisoning, inter-agent comms, cascading failure, human-agent trust, rogue agents.
- Attack Replay & Regression Detection
Snapshot and replay past attack payloads against the current rule set. Detects rule-regression: a payload that was previously blocked but is now allowed because rules were weakened or a pattern was missed. Each snapshot stores payload hash + verdict + evidence, enabling 'has our defense regressed since last check' audits. Borrowed from the ChronosFix 'fault time machine' pattern in agent infra competitions.
- Continuous Attestation
Subscribe an MCP server, skill or live agent workspace to recurring re-scanning (default 7-day cycle). Detects drift against the recorded evidence hash, revokes certification when the score drops below threshold, and exposes a machine-readable answer to 'is this still trustworthy right now'. Designed for rug-pull defence: certification without expiry is marketing.
- Multi-Client MCP Config Discovery & Audit
Auto-discover MCP server configurations across 14 client surfaces (Claude Desktop, Claude Code user+project, Cursor user+project, VS Code user+project, Windsurf, Gemini CLI, GitHub Copilot CLI, Augment, Zed, Cline, WorkBuddy) and statically audit them for privileged launch, runtime package fetch at startup, shell-interpreter invocation, non-registry provenance, inline plaintext credentials, insecure transport, wildcard bind, unauthenticated remote endpoints, project-level trust traps, namespace shadowing between servers, and 7 classes of toxic capability flows. PURELY STATIC: AIShield never executes any command defined in a scanned configuration - unlike scanners that spawn the server process to read tools/list.
- Security Scan
Scan an MCP server, AI skill or agent description against 264 MCP / 291 skill rule categories (OWASP MCP Top 10 + Agentic AI Top 10 + sandbox hardening). For skill assets, Markdown is treated as executable payload rather than documentation.
- Supply Chain & Hallucinated Package Audit
Offline detection of slopsquatting / AI-hallucinated dependencies in package.json, requirements.txt and pyproject.toml. Covers typosquat (Levenshtein), homoglyph poisoning, brand impersonation, composite hallucination (the ~50% of fabricated names that are NOT edit-distance-similar to any real package, e.g. react-codeshift), cross-registry confusion, dependency confusion, install-script poisoning, untrusted sources, unpinned versions and missing lockfiles. Zero network calls, zero package database.
- Trust Score Lookup
Return an agent's AIShield Trust Score (0-100) and certification level from the Agent Registry.
- Vertical-Domain Semantic Risk Scan
Domain-specific semantic risk screening for high-sensitivity verticals: finance (fraud inducement / unlicensed wealth management / pump-and-dump), medical (unlicensed diagnosis / false cure claims), and government/public-sector (sensitive topics / unauthorized disclosure). Sits on top of the generic OWASP rule set to catch agent output that is technically compliant but semantically dangerous in its context. Borrowed from the FinFlux 'financial semantic admission' pattern.