Skip to content
62 changes: 58 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,6 @@
<img src="assets/github_banner.jpg" alt="Trustabl — open source AI agent reliability" width="100%">
</p>

Find and automatically fix guardrail gaps, unsafe tools, missing validation, and
unbounded loops in Claude Agent SDK, OpenAI Agents SDK, Google ADK, LangChain,
CrewAI, and MCP agents — before production.

<p align="center">
<a href="LICENSE"><img src="https://img.shields.io/badge/license-Apache--2.0-blue" alt="License: Apache-2.0"></a>
<a href="https://github.com/trustabl/agent-reliability-analyzer/releases"><img src="https://img.shields.io/github/v/release/trustabl/agent-reliability-analyzer" alt="Latest release"></a>
Expand All @@ -25,6 +21,64 @@ CrewAI, and MCP agents — before production.

**Find what will make your AI agent fail — then fix it with one command.**

Deterministic static analysis for agent code, across nine SDKs and seven languages.
It runs entirely on your machine: no cloud scanner, no account, no code upload, no LLM.

---

<h3 align="center">Trustabl Partners</h3>
<p align="center">
<sub>One engine, seven front doors. Install it from the catalogue you already use.</sub>
</p>

<table align="center">
<tr>
<td align="center" width="170">
<a href="https://registry.modelcontextprotocol.io/?q=trustabl"><b>MCP Registry</b></a><br>
<sub>Scan from any<br>MCP-aware client</sub>
</td>
<td align="center" width="170">
<a href="https://claude.ai/directory"><b>Claude Directory</b></a><br>
<sub>Skills, agent and<br>scanner inside Claude</sub>
</td>
<td align="center" width="170">
<a href="https://marketplace.visualstudio.com/items?itemName=trustabl.trustabl"><b>VS Code</b></a><br>
<sub>Findings as you<br>write, in the editor</sub>
</td>
<td align="center" width="170">
<a href="https://cursor.directory/plugins/trustabl"><b>Cursor</b></a><br>
<sub>Same scan, wired<br>in as an MCP server</sub>
</td>
</tr>
<tr>
<td align="center">
<a href="https://github.com/marketplace/actions/trustabl-fix-agent-reliability-issues"><b>GitHub Actions</b></a><br>
<sub>Gate the build<br>on a severity threshold</sub>
</td>
<td align="center">
<a href="https://gitlab.com/explore/catalog/trustabl-ai/components"><b>GitLab CI/CD</b></a><br>
<sub>Published component<br>in the catalogue</sub>
</td>
<td align="center">
<a href="https://bitbucket.org/hoolisoftware/trustabl-pipe"><b>Bitbucket</b></a><br>
<sub>Official pipe, no<br>install step needed</sub>
</td>
<td align="center">
<a href="https://github.com/trustabl/agent-reliability-analyzer/releases"><b>CLI</b></a><br>
<sub>Homebrew, Scoop,<br>Docker or a binary</sub>
</td>
</tr>
</table>

<p align="center">
<sub>
Every one of these runs the same deterministic scan on your own machine.<br>
See <a href="docs/integrations.md">ecosystem integrations</a> for which agent SDKs are covered.
</sub>
</p>

---

Trustabl scans an agent repository for the gaps that break agents in production:
tool descriptions too vague for a model to know when to use them, missing retry
and timeout handling, untyped parameters, absent guardrails, and tool grants that
Expand Down
28 changes: 23 additions & 5 deletions docs/integrations.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,33 @@ listing lives.

---

## Where Trustabl is listed

The directories Trustabl is published in, and the ones a submission is open
with. Anything not on this list has no entry yet.

| Directory | Status | Since |
|---|---|---|
| [MCP Registry](https://registry.modelcontextprotocol.io/?q=trustabl) | **Listed** | 24 Sep 2026 |
| [Claude Directory](https://claude.ai/directory) | **Listed** | 29 Sep 2026 |
| [VS Code Marketplace](https://marketplace.visualstudio.com/items?itemName=trustabl.trustabl) | **Listed** | 11 Sep 2026 |
| [Cursor](https://cursor.directory/plugins/trustabl) | **Listed** | 11 Aug 2026 |
| [GitHub Marketplace](https://github.com/marketplace/actions/trustabl-fix-agent-reliability-issues) | **Listed** | — |
| [GitLab CI/CD Catalog](https://gitlab.com/explore/catalog/trustabl-ai/components) | **Listed** | — |
| [Bitbucket Pipes](https://bitbucket.org/hoolisoftware/trustabl-pipe) | **Listed** | 18 Aug 2026 |
| [in-toto](https://github.com/in-toto/friends/pull/122) | Submitted | 28 Sep 2026 |

---

## Agent frameworks

Every framework below is covered by the rule packs today. The order is the order
we are pursuing an official listing in each ecosystem's own directory.
Every framework below is covered by the rule packs today. The listing column says
whether that ecosystem's own directory carries an entry for Trustabl.

| # | Ecosystem | What Trustabl checks | Listing |
|---|---|---|---|
| 1 | **Google ADK** | Agents, tools, skills, plugins and callbacks | Not listed |
| 2 | **Claude Agent SDK** | Agents, tools, skills and hooks — unsafe tool grants, missing turn limits, prompt-injectable shell tools | Not listed |
| 2 | **Claude Agent SDK** | Agents, tools, skills and hooks — unsafe tool grants, missing turn limits, prompt-injectable shell tools | **Listed** |
| 3 | **Pydantic AI** | Typed tools, structured outputs, usage limits, idempotent mutations | Not listed |
| 4 | **OpenAI Agents SDK** | Agents, tools, handoffs and guardrails | Not listed |
| 5 | **Vercel AI SDK** | Untyped tools, missing step bounds, provider shell and file tools, fetch calls with no timeout | Not listed |
Expand Down Expand Up @@ -58,15 +76,15 @@ exposing a `scan` tool backed by the same analysis as `trustabl scan`:
}
```

Registry listing: not listed.
Registry listing: **[io.github.trustabl/agent-reliability-analyzer](https://registry.modelcontextprotocol.io/?q=trustabl)**, live since 24 September 2026.

---

## Policy and standards

| Ecosystem | Relationship | Listing |
|---|---|---|
| **in-toto** | Trustabl emits a signed scan attestation; in-toto makes it verifiable across the supply chain, so a verifier can prove an agent was checked against a known ruleset before it shipped | Not listed |
| **in-toto** | Trustabl emits a signed scan attestation; in-toto makes it verifiable across the supply chain, so a verifier can prove an agent was checked against a known ruleset before it shipped | [Submitted](https://github.com/in-toto/friends/pull/122) |
| **NVIDIA OpenShell** | Trustabl derives least-privilege policy from agent code, identity and required endpoints; OpenShell enforces it at runtime | Not listed |

See [`attestation.md`](attestation.md) for the attestation format.
Expand Down
Loading