{"id":9282,"name":"AIShield Security Scanner","description":"Open-source, local-first AI Agent security scanner and trust authority - the neutral trust layer and content-security plane of the 2026 Internet of Agents. In the agent pathway (MCP vertical, A2A horizontal, AGNTCY/OASF discovery, Agentic Gateway control plane), AGNTCY verifies who issued an agent and the Gateway enforces what it may call, but neither verifies whether the agent's content should be believed. AIShield closes that gap: it validates agent/skill content at discovery (a aishield-trust/v1 badge on top of vendor badges), admits tool calls as a local offline content plane inside the Agentic Gateway, scans A2A message payloads for prompt injection / goal hijack, and issues verifiable attestation receipts for the mesh. Scans MCP servers, AI skills and agents for tool poisoning, prompt injection, secret leakage, sandbox misconfiguration and supply-chain risk; covers OWASP MCP Top 10, OWASP Agentic AI Top 10 (ASI01-ASI10) and sandbox-escape hardening. Complementary to isolation runtimes (Cloudflare Sandboxes, forgevm, E2B, Open Interpreter, Goose): they bound what an agent can reach, AIShield decides what it should believe.","card_url":"https://aishield.tools/.well-known/agent-card.json","endpoint":"https://aishield.tools/api/v1/mcp","protocol_version":"0.3.0","first_seen":"2026-10-10T07:51:19.443857+00:00","last_verified":"2026-10-10T08:00:07.230137+00:00","card":{"mcp":{"endpoint":"https://aishield.tools/api/v1/mcp","transport":"streamable-http"},"url":"https://aishield.tools/api/v1/mcp","name":"AIShield Security Scanner","trust":{"badge":"https://aishield.tools/badge/aishield","schema":"aishield-trust/v1","authority":"aishield","guarantee":"static-only, never executes scanned config; offline; content-aware (prompt injection / tool poisoning / supply-chain drift)","verdict_url":"https://aishield.tools/api/v1/trust?src=https://github.com/lm203688/aishield","attestation_url":"https://aishield.tools/api/v1/attestation/trust?src=https://github.com/lm203688/aishield"},"skills":[{"id":"security_scan","name":"Security Scan","tags":["security","audit","mcp","agent"],"examples":["Scan this MCP server tool list for prompt-injection and tool-poisoning risk"],"description":"Scan an MCP server, AI skill or agent description against 264 MCP / 291 skill rule categories (OWASP MCP Top 10 + Agentic AI Top 10 + sandbox hardening). For skill assets, Markdown is treated as executable payload rather than documentation."},{"id":"agentic_audit","name":"Agentic AI Audit","tags":["agentic","owasp","audit"],"examples":["Audit my agent's delegation chain for ASI03 identity and ASI07 inter-agent risks"],"description":"Audit an AI agent against OWASP Agentic AI Top 10 (ASI01-ASI10): goal hijack, tool misuse, identity abuse, supply chain, code execution, memory poisoning, inter-agent comms, cascading failure, human-agent trust, rogue agents."},{"id":"supply_chain_audit","name":"Supply Chain & Hallucinated Package Audit","tags":["supply-chain","slopsquatting","typosquat","sbom","offline"],"examples":["Check this package.json for hallucinated or typosquatted dependencies","Does my requirements.txt install anything from a non-PyPI source?"],"description":"Offline detection of slopsquatting / AI-hallucinated dependencies in package.json, requirements.txt and pyproject.toml. Covers typosquat (Levenshtein), homoglyph poisoning, brand impersonation, composite hallucination (the ~50% of fabricated names that are NOT edit-distance-similar to any real package, e.g. react-codeshift), cross-registry confusion, dependency confusion, install-script poisoning, untrusted sources, unpinned versions and missing lockfiles. Zero network calls, zero package database."},{"id":"multi_client_config_scan","name":"Multi-Client MCP Config Discovery & Audit","tags":["mcp","config","discovery","static-analysis","namespace-shadowing","toxic-flow","local-first"],"examples":["Find every MCP server configured on this machine and tell me which ones are risky","Do any of my MCP servers shadow each other's tool names?","Which configured servers combine private-data read with untrusted network egress?"],"description":"Auto-discover MCP server configurations across 14 client surfaces (Claude Desktop, Claude Code user+project, Cursor user+project, VS Code user+project, Windsurf, Gemini CLI, GitHub Copilot CLI, Augment, Zed, Cline, WorkBuddy) and statically audit them for privileged launch, runtime package fetch at startup, shell-interpreter invocation, non-registry provenance, inline plaintext credentials, insecure transport, wildcard bind, unauthenticated remote endpoints, project-level trust traps, namespace shadowing between servers, and 7 classes of toxic capability flows. PURELY STATIC: AIShield never executes any command defined in a scanned configuration - unlike scanners that spawn the server process to read tools/list."},{"id":"agent_computer_preflight","name":"Agent Computer Pre-Flight Scan","tags":["agent-computer","sandbox","preflight","workspace","static-analysis","local-first","cloudflare-sandbox","forgevm","goose","open-interpreter"],"examples":["Is this workspace safe to boot an agent in?","Pre-flight scan the MCP servers and skills in /workspace before starting the sandbox","Does my container definition give the agent host access it should not have?"],"description":"Scan an agent workspace BEFORE the sandbox boots. Parses .mcp.json, forge / agent-forge, Goose and Open Interpreter configurations plus every skill file, scores each item, and returns a boot / review / refuse verdict. Complements isolation runtimes (Cloudflare Sandboxes and Containers, forgevm, E2B, Open Interpreter, Goose) which bound blast radius but do not inspect the content an agent loads inside the box. Also checks 11 sandbox-hardening rules on the box definition itself: mounted docker.sock, --privileged, host network/PID/IPC namespaces, cap_add ALL, CAP_SYS_ADMIN, seccomp=unconfined, --user 0, Kubernetes hostPath. PURELY STATIC: never spawns a command found in the workspace, never fetches the network."},{"id":"continuous_attestation","name":"Continuous Attestation","tags":["attestation","certification","rug-pull","monitoring","trust"],"examples":["Keep re-checking this MCP server every week and revoke its badge if it degrades","Is this agent still passing the security bar it was certified against?"],"description":"Subscribe an MCP server, skill or live agent workspace to recurring re-scanning (default 7-day cycle). Detects drift against the recorded evidence hash, revokes certification when the score drops below threshold, and exposes a machine-readable answer to 'is this still trustworthy right now'. Designed for rug-pull defence: certification without expiry is marketing."},{"id":"trust_score","name":"Trust Score Lookup","tags":["trust","registry","score"],"examples":["What is the trust score of did:aishield:7f3a2b1c9d4e5f6a8b0c1d2e3f4a5b6c?"],"description":"Return an agent's AIShield Trust Score (0-100) and certification level from the Agent Registry."},{"id":"identity_scan","name":"Agent Identity & Credential Scan","tags":["identity","nhi","agent-card","scope-attenuation","mtls","did","a2a"],"examples":["Is this AgentCard signed and is its scope least-privilege?","Does this service account use a never-expiring token?"],"description":"Scan the agent identity layer (NHI). Verifies AgentCard / agent-identity declarations are signed (JWS/DID/proof), credentials are short-lived rather than never-expiring, authorization is least-privilege (flags scope:'*' and over-broad grants that violate scope attenuation), and mTLS/DID verification is present. This is the fastest-moving front of 2026 agent security (the top A2A issues are all identity; Authentik's NHI wave; ANS/DNSid/Entra Agent ID). AIShield both issues trust certificates AND audits identity defects."},{"id":"network_scan","name":"Agent Network / Mesh Config Scan","tags":["network","mesh","cloudflare-mesh","vpc","reachability","exposure"],"examples":["Does this Mesh binding expose the entire account network to every agent?","Is any private resource in this config exposed to the public internet?"],"description":"Scan the agent network layer. Flags Cloudflare Mesh / VPC bindings that expose the whole account network to every agent (the gap Cloudflare itself admits: 'per-agent identity and policy evaluation are future work'), unauthenticated agent endpoints (auth: none), bind-to-all-interfaces exposure (0.0.0.0), and private/internal resources marked public:true. Answers the 'trust shallow' problem left open by A2A's signed AgentCard: content trust + identity attribution + network reachability."},{"id":"attack_replay","name":"Attack Replay & Regression Detection","tags":["attack-replay","regression","chronos-fix","snapshot","defense-hardening"],"examples":["Replay all attacks blocked last month and tell me which ones our current rules would still catch","Has our rule set regressed since the last attestation cycle?"],"description":"Snapshot and replay past attack payloads against the current rule set. Detects rule-regression: a payload that was previously blocked but is now allowed because rules were weakened or a pattern was missed. Each snapshot stores payload hash + verdict + evidence, enabling 'has our defense regressed since last check' audits. Borrowed from the ChronosFix 'fault time machine' pattern in agent infra competitions."},{"id":"vertical_risk_scan","name":"Vertical-Domain Semantic Risk Scan","tags":["vertical-risk","semantic-admission","finance","medical","gov","finflux"],"examples":["Scan this agent's financial advice output for fraud inducement language","Does this medical summary contain false-cure claims or unauthorized diagnoses?"],"description":"Domain-specific semantic risk screening for high-sensitivity verticals: finance (fraud inducement / unlicensed wealth management / pump-and-dump), medical (unlicensed diagnosis / false cure claims), and government/public-sector (sensitive topics / unauthorized disclosure). Sits on top of the generic OWASP rule set to catch agent output that is technically compliant but semantically dangerous in its context. Borrowed from the FinFlux 'financial semantic admission' pattern."}],"version":"4.11.0","llms_txt":"https://aishield.tools/llms.txt","provider":{"url":"https://aishield.tools","organization":"AIShield Project"},"description":"Open-source, local-first AI Agent security scanner and trust authority - the neutral trust layer and content-security plane of the 2026 Internet of Agents. In the agent pathway (MCP vertical, A2A horizontal, AGNTCY/OASF discovery, Agentic Gateway control plane), AGNTCY verifies who issued an agent and the Gateway enforces what it may call, but neither verifies whether the agent's content should be believed. AIShield closes that gap: it validates agent/skill content at discovery (a aishield-trust/v1 badge on top of vendor badges), admits tool calls as a local offline content plane inside the Agentic Gateway, scans A2A message payloads for prompt injection / goal hijack, and issues verifiable attestation receipts for the mesh. Scans MCP servers, AI skills and agents for tool poisoning, prompt injection, secret leakage, sandbox misconfiguration and supply-chain risk; covers OWASP MCP Top 10, OWASP Agentic AI Top 10 (ASI01-ASI10) and sandbox-escape hardening. Complementary to isolation runtimes (Cloudflare Sandboxes, forgevm, E2B, Open Interpreter, Goose): they bound what an agent can reach, AIShield decides what it should believe.","capabilities":{"streaming":false,"input_modes":["text/plain","application/json"],"output_modes":["text/plain","application/json"],"pushNotifications":false},"llms_full_txt":"https://aishield.tools/llms-full.txt","protocolVersion":"0.3.0","securitySchemes":{},"category_id_note":"The owasp_category values ASI01-ASI10 are AIShield's INTERNAL category IDs, not the official OWASP Top 10 for Agentic Applications (2026) identifiers. Only ASI01/ASI02/ASI03 coincide. Internal ASI04 (memory poisoning) = official ASI06 Memory & Context Poisoning; official ASI04 = Agentic Supply Chain. Internal ASI09 (cascading failure) = official ASI08. Official ASI05 (Unexpected Code Execution) has no dedicated internal category. The field carries TWO namespaces: MCP01-MCP10 are official OWASP MCP Top 10 codes; ASI01-ASI10 are AIShield internal. Most Agentic scanners emit MCP0x - of the 11 Agentic modules only scanner/memory_integrity_scan.py emits an internal ASI code (ASI04) - so filtering reports on ASI0x misses the majority of Agentic findings. Machine-readable crosswalk: the internal_to_owasp_agentic key returned by compliance_summary(). Source of truth: scanner/compliance.py (INTERNAL_ASI_TO_OWASP, OWASP_AGENTIC_2026, OWASP_AGENTIC_THREATS T1-T17).","agent_interconnect":{"note":"AIShield is a protocol-agnostic content-trust layer that sits on top of any agent interconnect protocol","schema":"AIP-AC/v1","trust_layer":"aishield-trust/v1","discovery_url":"https://aishield.tools/api/v1/registry/search?q=aishield","compatible_with":["AIP","AGNTCY","OASF","A2A"]},"aip_protocol_version":"1.0.0"},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T08:00:07.230137+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agenstry federation","source_url":"https://agenstry.com/docs","last_check":{"checked_at":"2026-10-10T08:00:07.230137+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://aishield.tools/.well-known/agent-card.json"],"skills":[{"skill_id":"agent_computer_preflight","name":"Agent Computer Pre-Flight Scan","description":"Scan an agent workspace BEFORE the sandbox boots. Parses .mcp.json, forge / agent-forge, Goose and Open Interpreter configurations plus every skill file, scores each item, and returns a boot / review / refuse verdict. Complements isolation runtimes (Cloudflare Sandboxes and Containers, forgevm, E2B, Open Interpreter, Goose) which bound blast radius but do not inspect the content an agent loads inside the box. Also checks 11 sandbox-hardening rules on the box definition itself: mounted docker.sock, --privileged, host network/PID/IPC namespaces, cap_add ALL, CAP_SYS_ADMIN, seccomp=unconfined, --user 0, Kubernetes hostPath. PURELY STATIC: never spawns a command found in the workspace, never fetches the network.","tags":["agent-computer","sandbox","preflight","workspace","static-analysis","local-first","cloudflare-sandbox","forgevm","goose","open-interpreter"],"quality_warning":false},{"skill_id":"identity_scan","name":"Agent Identity & Credential Scan","description":"Scan the agent identity layer (NHI). Verifies AgentCard / agent-identity declarations are signed (JWS/DID/proof), credentials are short-lived rather than never-expiring, authorization is least-privilege (flags scope:'*' and over-broad grants that violate scope attenuation), and mTLS/DID verification is present. This is the fastest-moving front of 2026 agent security (the top A2A issues are all identity; Authentik's NHI wave; ANS/DNSid/Entra Agent ID). AIShield both issues trust certificates AND audits identity defects.","tags":["identity","nhi","agent-card","scope-attenuation","mtls","did","a2a"],"quality_warning":false},{"skill_id":"network_scan","name":"Agent Network / Mesh Config Scan","description":"Scan the agent network layer. Flags Cloudflare Mesh / VPC bindings that expose the whole account network to every agent (the gap Cloudflare itself admits: 'per-agent identity and policy evaluation are future work'), unauthenticated agent endpoints (auth: none), bind-to-all-interfaces exposure (0.0.0.0), and private/internal resources marked public:true. Answers the 'trust shallow' problem left open by A2A's signed AgentCard: content trust + identity attribution + network reachability.","tags":["network","mesh","cloudflare-mesh","vpc","reachability","exposure"],"quality_warning":false},{"skill_id":"agentic_audit","name":"Agentic AI Audit","description":"Audit an AI agent against OWASP Agentic AI Top 10 (ASI01-ASI10): goal hijack, tool misuse, identity abuse, supply chain, code execution, memory poisoning, inter-agent comms, cascading failure, human-agent trust, rogue agents.","tags":["agentic","owasp","audit"],"quality_warning":false},{"skill_id":"attack_replay","name":"Attack Replay & Regression Detection","description":"Snapshot and replay past attack payloads against the current rule set. Detects rule-regression: a payload that was previously blocked but is now allowed because rules were weakened or a pattern was missed. Each snapshot stores payload hash + verdict + evidence, enabling 'has our defense regressed since last check' audits. Borrowed from the ChronosFix 'fault time machine' pattern in agent infra competitions.","tags":["attack-replay","regression","chronos-fix","snapshot","defense-hardening"],"quality_warning":false},{"skill_id":"continuous_attestation","name":"Continuous Attestation","description":"Subscribe an MCP server, skill or live agent workspace to recurring re-scanning (default 7-day cycle). Detects drift against the recorded evidence hash, revokes certification when the score drops below threshold, and exposes a machine-readable answer to 'is this still trustworthy right now'. Designed for rug-pull defence: certification without expiry is marketing.","tags":["attestation","certification","rug-pull","monitoring","trust"],"quality_warning":false},{"skill_id":"multi_client_config_scan","name":"Multi-Client MCP Config Discovery & Audit","description":"Auto-discover MCP server configurations across 14 client surfaces (Claude Desktop, Claude Code user+project, Cursor user+project, VS Code user+project, Windsurf, Gemini CLI, GitHub Copilot CLI, Augment, Zed, Cline, WorkBuddy) and statically audit them for privileged launch, runtime package fetch at startup, shell-interpreter invocation, non-registry provenance, inline plaintext credentials, insecure transport, wildcard bind, unauthenticated remote endpoints, project-level trust traps, namespace shadowing between servers, and 7 classes of toxic capability flows. PURELY STATIC: AIShield never executes any command defined in a scanned configuration - unlike scanners that spawn the server process to read tools/list.","tags":["mcp","config","discovery","static-analysis","namespace-shadowing","toxic-flow","local-first"],"quality_warning":false},{"skill_id":"security_scan","name":"Security Scan","description":"Scan an MCP server, AI skill or agent description against 264 MCP / 291 skill rule categories (OWASP MCP Top 10 + Agentic AI Top 10 + sandbox hardening). For skill assets, Markdown is treated as executable payload rather than documentation.","tags":["security","audit","mcp","agent"],"quality_warning":false},{"skill_id":"supply_chain_audit","name":"Supply Chain & Hallucinated Package Audit","description":"Offline detection of slopsquatting / AI-hallucinated dependencies in package.json, requirements.txt and pyproject.toml. Covers typosquat (Levenshtein), homoglyph poisoning, brand impersonation, composite hallucination (the ~50% of fabricated names that are NOT edit-distance-similar to any real package, e.g. react-codeshift), cross-registry confusion, dependency confusion, install-script poisoning, untrusted sources, unpinned versions and missing lockfiles. Zero network calls, zero package database.","tags":["supply-chain","slopsquatting","typosquat","sbom","offline"],"quality_warning":false},{"skill_id":"trust_score","name":"Trust Score Lookup","description":"Return an agent's AIShield Trust Score (0-100) and certification level from the Agent Registry.","tags":["trust","registry","score"],"quality_warning":false},{"skill_id":"vertical_risk_scan","name":"Vertical-Domain Semantic Risk Scan","description":"Domain-specific semantic risk screening for high-sensitivity verticals: finance (fraud inducement / unlicensed wealth management / pump-and-dump), medical (unlicensed diagnosis / false cure claims), and government/public-sector (sensitive topics / unauthorized disclosure). Sits on top of the generic OWASP rule set to catch agent output that is technically compliant but semantically dangerous in its context. Borrowed from the FinFlux 'financial semantic admission' pattern.","tags":["vertical-risk","semantic-admission","finance","medical","gov","finflux"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":2,"passed":2},"recent_checks":[{"card_url":"https://aishield.tools/.well-known/agent-card.json","checked_at":"2026-10-10T08:00:07.230137+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://aishield.tools/.well-known/agent-card.json","checked_at":"2026-10-10T07:51:19.443857+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T08:00:07.230137+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T07:51:19.443857+00:00","state":"unconfirmed","http_status":200,"detail":"Advertised A2A task lookup method was not found"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://aishield.tools/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T08:00:07.230137+00:00","latest_card_check":{"checked_at":"2026-10-10T08:00:07.230137+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T08:00:07.230137+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T08:00:07.230137+00:00","endpoint_tls_reachable":true,"protocol_check_state":"unconfirmed","protocol_checked_at":"2026-10-10T07:51:19.443857+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}