KYA™ · Know Your Agent

Agent Trust Registry

Public registry of preliminary KYA™ signals for source-visible agent projects.
Scores support due diligence and capability controls. They are not final security certifications.

30
Agents tracked
30
Preliminary scans
2578
Findings flagged
1420
CVEs detected
Static analysis + OSV.dev CVE scan + NVIDIA Llama 70B audit · Questions? [email protected]
Tiers
Sovereign ≥85
Partner ≥75
Node ≥60
Rejected <58
Blended score: 30% manual baseline + 70% live analysis
Audit Methodology

How we score agents

Every score in this registry is produced by a three-stage preliminary pipeline run against a prioritized sample of the agent's public source code, no installs, no clones, no marketing materials. We inspect capabilities, check dependencies, and run an independent AI review.

Scores are a blend of our manual safety baseline (30%) and the live analysis result (70%). The baseline captures things code can't show: organizational maturity, incident history, and published safety disclosures. The live analysis reflects what's actually in the codebase today.

On false positives. Static analysis is inherently noisy. A CLI tool using child_process looks the same as a malicious subprocess call. An agent that legitimately browses the web will flag network patterns. We surface these signals, we don't suppress them, because the operator needs to make that judgment for their context. Over time, our detection patterns improve as we build type-aware and context-aware rules. Treat scores as a starting point for due diligence, not a final verdict.

01

Static code analysis

Pattern-based scan across a prioritized source sample fetched via GitHub API, no disk writes, no execution. We flag capabilities such as shell execution, code evaluation, and network access for review. A capability signal is not, by itself, a confirmed vulnerability.

02

Dependency CVE scan

We parse package.json and requirements.txt files without installing anything. Each dependency is queried against OSV.dev, Google's open vulnerability database, using their batch API. CVSS ≥7.0 is flagged as High, 4.0-7.0 as Medium. We also flag unpinned version ranges (^, ~, *) as supply chain risk.

03

AI-powered semantic audit

Source files are passed to a large language model (Llama 3.1 70B via NVIDIA NIM) with a structured security prompt. The model looks for issues static patterns miss: unsafe prompt construction, missing input validation on tool calls, context leakage between sessions, and missing human-in-the-loop checkpoints. This stage catches behavioral risks, not just syntactic ones.

04

Score composition

Five dimensions are scored: Framework (design-level guardrails), Code Health (quality and safety of implementation), Tool Permissions (blast radius of tool access), Prompt Safety (injection resistance), and Loop Safety (termination guarantees). These combine into a raw score, which is then blended with our manual baseline. Scores are re-run periodically as frameworks evolve.

General Open Source
78
UI-TARS
ByteDance
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:6
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
4/5 prioritized files · 582f3a7
Code Source Available
77
Claude Code
Anthropic
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:3 I:79
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
20/26 prioritized files · b3f0e50
General Open Source
76
LangChain Agent
LangChain Inc.
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:2
Prompt Safety
Top finding ████████████████████████████████████, classified
60/2581 prioritized files · 79cab2d
Multi-Agent Open Source
76
LangGraph
LangChain Inc.
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
20 deps scanned via OSV.dev
60/467 prioritized files · 81bf17b
Code Open Source
76
OpenHands
All Hands AI
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:3 I:22 CVE:1
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
97 deps scanned via OSV.dev
37/958 prioritized files · 4524a91
General Open Source
76
ZeroClaw
ZeroClaw Labs
Partner Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:2 I:79
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
30 deps scanned via OSV.dev
60/104 prioritized files · c9b08ab
General Open Source
73
Moltis
Moltis Org
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:3 I:27
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
23 deps scanned via OSV.dev
60/295 prioritized files · 9c7ea07
General Open Source
73
IronClaw
Near AI
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:3 I:11 CVE:1
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
49 deps scanned via OSV.dev
54/607 prioritized files · 21f8fdd
General Open Source
72
PicoClaw
Sipeed
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:2 I:5
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
50 deps scanned via OSV.dev
60/64 prioritized files · bbf6893
Multi-Agent Open Source
71
CrewAI
CrewAI Inc.
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:3 I:36
Prompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
60/1328 prioritized files · 92eb5f9
General Open Source
69
OpenClaw
OpenClaw Labs
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:4 I:2 CVE:2
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
69 deps scanned via OSV.dev
60/30600 prioritized files · aa627d2
General Open Source
65
PydanticAI
Pydantic
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:3 M:3 I:3
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
47/760 prioritized files · 037302d
Multi-Agent Open Source
64
AutoGen
Microsoft Research
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:6 I:9 CVE:4
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
38 deps scanned via OSV.dev
60/593 prioritized files · 027ecf0
Multi-Agent Open Source
62
OpenAI Swarm
OpenAI
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:4 M:3 I:5
Loop SafetyPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
55/63 prioritized files · 6af0b4c
General Open Source
60
Agno
Agno (ex-Phidata)
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:394 I:1 CVE:392
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
346 deps scanned via OSV.dev
60/4814 prioritized files · 56eae14
General Open Source
60
UI-TARS Desktop
ByteDance
Node Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:215 I:63 CVE:213
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
376 deps scanned via OSV.dev
60/1252 prioritized files · c2ad42e
General Open Source
58
Strands Agents
AWS / Strands
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:7 I:21 CVE:4
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
130 deps scanned via OSV.dev
60/1481 prioritized files · 24bc5c3
General Open Source
56
LlamaIndex
LlamaIndex Inc.
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:106 I:1 CVE:103
Dependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████, classified
217 deps scanned via OSV.dev
60/3899 prioritized files · d2ac544
General Open Source
56
Semantic Kernel
Microsoft
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:90 I:11 CVE:89
Loop SafetyDependency VulnerabilityPrompt Safety
Top finding ████████████████████████████████████, classified
34 deps scanned via OSV.dev
60/1270 prioritized files · d8ec449
General Open Source
56
Hermes Agent
NousResearch
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:12 I:7 CVE:10
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
159 deps scanned via OSV.dev
38/7174 prioritized files · 6327930
General Open Source
55
AutoGPT
Significant Gravitas
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:1 M:20 I:21 CVE:18
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
155 deps scanned via OSV.dev
20/2733 prioritized files · 32a43d0
General Open Source
55
OpenFang
RightNow AI
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:23 I:392 CVE:21
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
9 deps scanned via OSV.dev
36/39 prioritized files · acf2587
General Open Source
55
Cherry Studio
CherryHQ
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:76 I:14 CVE:74
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
521 deps scanned via OSV.dev
49/4722 prioritized files · 99a2c18
General Open Source
54
Mastra
Mastra AI
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:80 I:55 CVE:78
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
172 deps scanned via OSV.dev
60/9093 prioritized files · 722b7af
Multi-Agent Open Source
54
Paperclip
PaperclipAI
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:17 I:45 CVE:14
Dependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
125 deps scanned via OSV.dev
60/3527 prioritized files · 9ef3b08
Research Open Source
49
Dexter
virattt
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:3 M:17 I:12 CVE:15
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
35 deps scanned via OSV.dev
60/218 prioritized files · ecaed30
General Open Source
48
smolagents
Hugging Face
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:3 M:194 I:35 CVE:192
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
26 deps scanned via OSV.dev
27/77 prioritized files · 30bb116
Multi-Agent Open Source
47
MetaGPT
FoundationAgents
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:3 M:142 I:13 CVE:140
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
97 deps scanned via OSV.dev
60/919 prioritized files · 11cdf46
Multi-Agent Open Source
47
Agency Swarm
VRSEN
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:2 M:30 I:12 CVE:28
Loop SafetyDependency VulnerabilityTool Abuse Risk
Top finding ████████████████████████████████████, classified
22 deps scanned via OSV.dev
60/401 prioritized files · 5cd5a0d
General Open Source
45
Nanobot
HKUDS
Rejected Preliminary scan Sep 4, 2026 Static refresh · AI findings preserved
H:3 M:23 I:42 CVE:21
Loop SafetyDependency VulnerabilityPrompt SafetyTool Abuse Risk
Top finding ████████████████████████████████████, classified
50 deps scanned via OSV.dev
30/886 prioritized files · 3d40ed8

Apply for a KYA™ evaluation.

Approved capabilities depend on your agent, operator, jurisdiction, cohort, and licensed infrastructure partners. A preliminary registry score does not guarantee financial access.

Get Quick Sell token