From 10cc876e0a1429463c0cf3228d445fab985dd351 Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 09:47:47 +0800 Subject: [PATCH 1/8] docs: add a partner availability table to the README Trustabl is installable from seven catalogues and the README named none of them. Someone arriving from a search has no way to tell that it already runs in their editor or CI without reading to the install section. Every link was checked to resolve before being added. Signed-off-by: sairenchristianbuerano --- README.md | 55 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) diff --git a/README.md b/README.md index e68aaeb4..5c7a74da 100644 --- a/README.md +++ b/README.md @@ -21,6 +21,61 @@ CrewAI, and MCP agents — before production. Output formats

+--- + +

Trustabl, where you already work

+

+ One engine, seven front doors. Install it from the catalogue you already use. +

+ + + + + + + + + + + + + + +
+ MCP Registry
+ Scan from any
MCP-aware client
+
+ Claude Directory
+ Skills, agent and
scanner inside Claude
+
+ VS Code
+ Findings as you
write, in the editor
+
+ Cursor
+ Same scan, wired
in as an MCP server
+
+ GitHub Actions
+ Gate the build
on a severity threshold
+
+ GitLab CI/CD
+ Published component
in the catalogue
+
+ Bitbucket
+ Official pipe, no
install step needed
+
+ CLI
+ Homebrew, Scoop,
Docker or a binary
+
+ +

+ + Every one of these runs the same deterministic scan on your own machine.
+ See ecosystem integrations for which agent SDKs are covered. +
+

+ +--- + # Trustabl — find and fix AI agent reliability gaps **Find what will make your AI agent fail — then fix it with one command.** From 41e61571dcd9f4382d00d203f95530d573cab604 Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 09:50:17 +0800 Subject: [PATCH 2/8] docs: lead with the title, a short description, then the partners The title sat below the banner, a tagline and twelve badges, so the first thing a reader met was metadata. Move it to the top, follow it with two lines saying what Trustabl is, then the partner table. Badges move below. The old tagline duplicated the line under the title, so it is dropped rather than repeated. Signed-off-by: sairenchristianbuerano --- README.md | 39 +++++++++++++++++++-------------------- 1 file changed, 19 insertions(+), 20 deletions(-) diff --git a/README.md b/README.md index 5c7a74da..afca8c10 100644 --- a/README.md +++ b/README.md @@ -2,24 +2,12 @@ Trustabl — open source AI agent reliability

-Find and automatically fix guardrail gaps, unsafe tools, missing validation, and -unbounded loops in Claude Agent SDK, OpenAI Agents SDK, Google ADK, LangChain, -CrewAI, and MCP agents — before production. +# Trustabl — find and fix AI agent reliability gaps -

- License: Apache-2.0 - Latest release - Total downloads - Tests - Go version -
- Detection rule count - 9 SDKs supported - 7 languages supported - 5 detection scopes - Analyzed surfaces - Output formats -

+**Find what will make your AI agent fail — then fix it with one command.** + +Deterministic static analysis for agent code, across nine SDKs and seven languages. +It runs entirely on your machine: no cloud scanner, no account, no code upload, no LLM. --- @@ -76,9 +64,20 @@ CrewAI, and MCP agents — before production. --- -# Trustabl — find and fix AI agent reliability gaps - -**Find what will make your AI agent fail — then fix it with one command.** +

+ License: Apache-2.0 + Latest release + Total downloads + Tests + Go version +
+ Detection rule count + 9 SDKs supported + 7 languages supported + 5 detection scopes + Analyzed surfaces + Output formats +

Trustabl scans an agent repository for the gaps that break agents in production: tool descriptions too vague for a model to know when to use them, missing retry From 500ef6ced4b98b4876e75a8575cc8f11c49141ba Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 09:52:02 +0800 Subject: [PATCH 3/8] docs: put the badges back under the banner Signed-off-by: sairenchristianbuerano --- README.md | 31 +++++++++++++++---------------- 1 file changed, 15 insertions(+), 16 deletions(-) diff --git a/README.md b/README.md index afca8c10..25a42cb4 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,21 @@ Trustabl — open source AI agent reliability

+

+ License: Apache-2.0 + Latest release + Total downloads + Tests + Go version +
+ Detection rule count + 9 SDKs supported + 7 languages supported + 5 detection scopes + Analyzed surfaces + Output formats +

+ # Trustabl — find and fix AI agent reliability gaps **Find what will make your AI agent fail — then fix it with one command.** @@ -62,22 +77,6 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload,

---- - -

- License: Apache-2.0 - Latest release - Total downloads - Tests - Go version -
- Detection rule count - 9 SDKs supported - 7 languages supported - 5 detection scopes - Analyzed surfaces - Output formats -

Trustabl scans an agent repository for the gaps that break agents in production: tool descriptions too vague for a model to know when to use them, missing retry From 34ff9a277be520908d9443c88541a840579404bb Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 09:54:19 +0800 Subject: [PATCH 4/8] docs: title the section Trustabl Partners and close it with a rule The closing rule was lost when the badges moved, so the partner table ran straight into the body text. Signed-off-by: sairenchristianbuerano --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 25a42cb4..2800c12d 100644 --- a/README.md +++ b/README.md @@ -26,7 +26,7 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload, --- -

Trustabl, where you already work

+

Trustabl Partners

One engine, seven front doors. Install it from the catalogue you already use.

@@ -77,6 +77,7 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload,

+--- Trustabl scans an agent repository for the gaps that break agents in production: tool descriptions too vague for a model to know when to use them, missing retry From 54645cf06a31aaf653b5b70b006c2e84ea536293 Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 09:57:27 +0800 Subject: [PATCH 5/8] docs: record where Trustabl is actually listed The integrations page said "Not listed" everywhere, which was true when it was written and is now wrong in three places: the MCP Registry entry is live, the Claude plugin is published, and the in-toto submission is open. Adds a summary table of the eight directories near the top, so the current state is answerable without reading the whole page, and corrects the stale per-section statuses. Signed-off-by: sairenchristianbuerano --- docs/integrations.md | 28 +++++++++++++++++++++++----- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/docs/integrations.md b/docs/integrations.md index 12e181b3..23b8dd62 100644 --- a/docs/integrations.md +++ b/docs/integrations.md @@ -14,15 +14,33 @@ listing lives. --- +## Where Trustabl is listed + +The directories Trustabl is published in, and the ones a submission is open +with. Anything not on this list has no entry yet. + +| Directory | Status | Since | +|---|---|---| +| [MCP Registry](https://registry.modelcontextprotocol.io/?q=trustabl) | **Listed** | 24 Sep 2026 | +| [Claude Directory](https://claude.ai/directory) | **Listed** | 29 Sep 2026 | +| [VS Code Marketplace](https://marketplace.visualstudio.com/items?itemName=trustabl.trustabl) | **Listed** | 11 Sep 2026 | +| [Cursor](https://cursor.directory/plugins/trustabl) | **Listed** | 11 Aug 2026 | +| [GitHub Marketplace](https://github.com/marketplace/actions/trustabl-fix-agent-reliability-issues) | **Listed** | — | +| [GitLab CI/CD Catalog](https://gitlab.com/explore/catalog/trustabl-ai/components) | **Listed** | — | +| [Bitbucket Pipes](https://bitbucket.org/hoolisoftware/trustabl-pipe) | **Listed** | 18 Aug 2026 | +| [in-toto](https://github.com/in-toto/friends/pull/122) | Submitted | 28 Sep 2026 | + +--- + ## Agent frameworks -Every framework below is covered by the rule packs today. The order is the order -we are pursuing an official listing in each ecosystem's own directory. +Every framework below is covered by the rule packs today. The listing column says +whether that ecosystem's own directory carries an entry for Trustabl. | # | Ecosystem | What Trustabl checks | Listing | |---|---|---|---| | 1 | **Google ADK** | Agents, tools, skills, plugins and callbacks | Not listed | -| 2 | **Claude Agent SDK** | Agents, tools, skills and hooks — unsafe tool grants, missing turn limits, prompt-injectable shell tools | Not listed | +| 2 | **Claude Agent SDK** | Agents, tools, skills and hooks — unsafe tool grants, missing turn limits, prompt-injectable shell tools | **Listed** | | 3 | **Pydantic AI** | Typed tools, structured outputs, usage limits, idempotent mutations | Not listed | | 4 | **OpenAI Agents SDK** | Agents, tools, handoffs and guardrails | Not listed | | 5 | **Vercel AI SDK** | Untyped tools, missing step bounds, provider shell and file tools, fetch calls with no timeout | Not listed | @@ -58,7 +76,7 @@ exposing a `scan` tool backed by the same analysis as `trustabl scan`: } ``` -Registry listing: not listed. +Registry listing: **[io.github.trustabl/agent-reliability-analyzer](https://registry.modelcontextprotocol.io/?q=trustabl)**, live since 24 September 2026. --- @@ -66,7 +84,7 @@ Registry listing: not listed. | Ecosystem | Relationship | Listing | |---|---|---| -| **in-toto** | Trustabl emits a signed scan attestation; in-toto makes it verifiable across the supply chain, so a verifier can prove an agent was checked against a known ruleset before it shipped | Not listed | +| **in-toto** | Trustabl emits a signed scan attestation; in-toto makes it verifiable across the supply chain, so a verifier can prove an agent was checked against a known ruleset before it shipped | [Submitted](https://github.com/in-toto/friends/pull/122) | | **NVIDIA OpenShell** | Trustabl derives least-privilege policy from agent code, identity and required endpoints; OpenShell enforces it at runtime | Not listed | See [`attestation.md`](attestation.md) for the attestation format. From eb359e32c2f7389495db87b7e50801a971fb29ed Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 10:09:06 +0800 Subject: [PATCH 6/8] docs: raise Trustabl Partners to a second-level heading Signed-off-by: sairenchristianbuerano --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 2800c12d..d0ebe7b3 100644 --- a/README.md +++ b/README.md @@ -26,7 +26,7 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload, --- -

Trustabl Partners

+

Trustabl Partners

One engine, seven front doors. Install it from the catalogue you already use.

From 5276c018e2529cedd03dc87f85ebb644745f60c2 Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 10:10:49 +0800 Subject: [PATCH 7/8] docs: add a partner badge strip, drop the heading underline GitHub draws a bottom border on every h1 and h2 in markdown, so raising the heading added a rule under it. Back to h3, with a row of branded badges carrying the visual weight instead. Every badge was checked to render with its logo before being added. VS Code has no icon in the badge provider's set, so that one is a plain colour rather than a wrong logo. Signed-off-by: sairenchristianbuerano --- README.md | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index d0ebe7b3..a4b9f891 100644 --- a/README.md +++ b/README.md @@ -26,9 +26,20 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload, --- -

Trustabl Partners

+

Trustabl Partners

- One engine, seven front doors. Install it from the catalogue you already use. + Published in eight catalogues. Install it from the one you already use. +

+ +

+ MCP Registry + Claude Directory + VS Code + Cursor + GitHub Actions + GitLab CI%2FCD + Bitbucket Pipes + Homebrew %C2%B7 Scoop %C2%B7 Docker

From 1039b03e8392d277e6cbcafaaf1eabc01553cdd2 Mon Sep 17 00:00:00 2001 From: sairenchristianbuerano Date: Tue, 29 Sep 2026 10:12:11 +0800 Subject: [PATCH 8/8] docs: remove the partner badge strip Signed-off-by: sairenchristianbuerano --- README.md | 13 +------------ 1 file changed, 1 insertion(+), 12 deletions(-) diff --git a/README.md b/README.md index a4b9f891..2800c12d 100644 --- a/README.md +++ b/README.md @@ -28,18 +28,7 @@ It runs entirely on your machine: no cloud scanner, no account, no code upload,

Trustabl Partners

- Published in eight catalogues. Install it from the one you already use. -

- -

- MCP Registry - Claude Directory - VS Code - Cursor - GitHub Actions - GitLab CI%2FCD - Bitbucket Pipes - Homebrew %C2%B7 Scoop %C2%B7 Docker + One engine, seven front doors. Install it from the catalogue you already use.