Skip to main content
Glama

AgentAvow Trust

Scan a package

scan_package
Read-onlyIdempotent

Scan a published package (npm, PyPI, crates, Docker, or Hugging Face) with AgentAvow. Returns one of three answers with its reason (Safe to connect, Review before you connect, or Do not connect), a 0-100 trust score, an adoption score from real usage (downloads per week), findings with remediation, and a signed attestation. Also reports published advisories that affect the scanned version, the maintainer's deprecation notice, repo-vs-artifact drift (files shipped that aren't in the source), and AgentAvow's behavioral sandbox results when available. Scans the latest version unless version (or a pin in the name) names one. Read-only; calls agentavow.com.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesPackage name, e.g. 'chalk' (or 'org/model' for hf).
forceNoRe-scan now instead of returning the cached verdict (results cache ~1h). Use after a new version ships.
surfaceNoAlias for registry.
versionNoExact version to scan, e.g. '5.3.0'. Optional: the latest version by default. A pin in the name ('chalk@5.3.0', 'requests==2.32.5') works too.
registryNoPackage registry: npm, pypi, crates, docker, or hf.
ecosystemNoAlias for registry.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
highNoHigh findings, static and sandbox.
tierNoTrust tier for the score (detail, not the headline).
cachedNoServed from the ~1h cache.
signedNoTrue when a signed (Ed25519/JWS) attestation backs this.
targetYesWhat was scanned, as given.
installNoInstall command, only when nothing blocks it.
sandboxNoWhat the behavioral sandbox observed; null if it does not apply.
verdictYesBinary form of the decision, kept for older clients.
adoptionNoThe adoption score: real usage (downloads per week, stars or installs). Never changes the decision.
criticalNoCritical findings, static and sandbox.
decisionYesThe answer to lead with: safe = Safe to connect, review = Review before you connect, do_not_connect = Do not connect.
incidentNoKnown past compromise (context only, never scored).
certifiedNoMatches the signed attestation's certified.eligible.
subscoresNoPer-category 0-100 scores behind the trust score.
deprecatedNoThe maintainer's deprecation notice, or null.
report_urlYesFull report page.
scanned_atNoWhen the scan ran (ISO 8601, UTC).
verify_urlNoHow to verify offline.
target_typeYesgithub, npm, pypi, crates, docker, hf, or mcp.
trust_scoreYesTrust score, 0-100. Evidence under the decision.
published_atNoWhen that version was published.
top_findingsNoUp to five most important findings.
certified_markNoCertified and safe: show the Certified mark.
decision_finalYesFalse while the behavioral sandbox is still running; the decision can still change.
findings_totalNoAll findings, every severity.
rescan_pendingNoA fresh scan was started; this is the previous result.
verdict_reasonNoMachine reason for the binary verdict, e.g. clean, blocking_findings, thin_coverage.
decision_reasonYesOne sentence naming what decided it.
package_versionNoPackage version scanned.
report_json_urlNoThe full verdict as JSON.
static_findings_totalNoFindings from static analysis only.
advisories_affecting_versionNoPublished advisories that affect this version.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • addedInput schema / properties / version
      Added value: +{
      +  "description": "Exact version to scan, e.g. '5.3.0'. Optional: the latest version by default. A pin in the name ('chalk@5.3.0', 'requests==2.32.5') works too.",
      +  "maxLength": 64,
      +  "type": "string"
      +}
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "adoption": {
      +      "description": "The adoption score: real usage (downloads per week, stars or installs). Never changes the decision.",
      +      "properties": {
      +        "count": {
      +          "type": "integer"
      +        },
      +        "score_0_100": {
      +          "type": "integer"
      +        },
      +        "unit": {
      +          "type": "string"
      +        }
      +      },
      +      "type": [
      +        "object",
      +        "null"
      +      ]
      +    },
      +    "advisories_affecting_version": {
      +      "description": "Published advisories that affect this version.",
      +      "items": {
      +        "type": "object"
      +      },
      +      "type": "array"
      +    },
      +    "cached": {
      +      "description": "Served from the ~1h cache.",
      +      "type": "boolean"
      +    },
      +    "certified": {
      +      "description": "Matches the signed attestation's certified.eligible.",
      +      "type": "boolean"
      +    },
      +    "certified_mark": {
      +      "description": "Certified and safe: show the Certified mark.",
      +      "type": "boolean"
      +    },
      +    "critical": {
      +      "description": "Critical findings, static and sandbox.",
      +      "minimum": 0,
      +      "type": "integer"
      +    },
      +    "decision": {
      +      "description": "The answer to lead with: safe = Safe to connect, review = Review before you connect, do_not_connect = Do not connect.",
      +      "enum": [
      +        "safe",
      +        "review",
      +        "do_not_connect"
      +      ],
      +      "type": "string"
      +    },
      +    "decision_final": {
      +      "description": "False while the behavioral sandbox is still running; the decision can still change.",
      +      "type": "boolean"
      +    },
      +    "decision_reason": {
      +      "description": "One sentence naming what decided it.",
      +      "type": "string"
      +    },
      +    "deprecated": {
      +      "description": "The maintainer's deprecation notice, or null.",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "findings_total": {
      +      "description": "All findings, every severity.",
      +      "minimum": 0,
      +      "type": "integer"
      +    },
      +    "high": {
      +      "description": "High findings, static and sandbox.",
      +      "minimum": 0,
      +      "type": "integer"
      +    },
      +    "incident": {
      +      "description": "Known past compromise (context only, never scored).",
      +      "type": [
      +        "object",
      +        "null"
      +      ]
      +    },
      +    "install": {
      +      "description": "Install command, only when nothing blocks it.",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "package_version": {
      +      "description": "Package version scanned.",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "published_at": {
      +      "description": "When that version was published.",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "report_json_url": {
      +      "description": "The full verdict as JSON.",
      +      "type": "string"
      +    },
      +    "report_url": {
      +      "description": "Full report page.",
      +      "type": "string"
      +    },
      +    "rescan_pending": {
      +      "description": "A fresh scan was started; this is the previous result.",
      +      "type": "boolean"
      +    },
      +    "sandbox": {
      +      "description": "What the behavioral sandbox observed; null if it does not apply.",
      +      "type": [
      +        "object",
      +        "null"
      +      ]
      +    },
      +    "scanned_at": {
      +      "description": "When the scan ran (ISO 8601, UTC).",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "signed": {
      +      "description": "True when a signed (Ed25519/JWS) attestation backs this.",
      +      "type": "boolean"
      +    },
      +    "static_findings_total": {
      +      "description": "Findings from static analysis only.",
      +      "minimum": 0,
      +      "type": "integer"
      +    },
      +    "subscores": {
      +      "additionalProperties": {
      +        "type": [
      +          "number",
      +          "null"
      +        ]
      +      },
      +      "description": "Per-category 0-100 scores behind the trust score.",
      +      "type": "object"
      +    },
      +    "target": {
      +      "description": "What was scanned, as given.",
      +      "type": "string"
      +    },
      +    "target_type": {
      +      "description": "github, npm, pypi, crates, docker, hf, or mcp.",
      +      "type": "string"
      +    },
      +    "tier": {
      +      "description": "Trust tier for the score (detail, not the headline).",
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "top_findings": {
      +      "description": "Up to five most important findings.",
      +      "items": {
      +        "properties": {
      +          "count": {
      +            "description": "How many times it occurs.",
      +            "type": "integer"
      +          },
      +          "remediation": {
      +            "description": "How to fix it.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "severity": {
      +            "description": "critical, high, medium, or low.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "what": {
      +            "description": "What was found.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "where": {
      +            "description": "File and line, if file-based.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          }
      +        },
      +        "type": "object"
      +      },
      +      "type": "array"
      +    },
      +    "trust_score": {
      +      "description": "Trust score, 0-100. Evidence under the decision.",
      +      "maximum": 100,
      +      "minimum": 0,
      +      "type": "integer"
      +    },
      +    "verdict": {
      +      "description": "Binary form of the decision, kept for older clients.",
      +      "enum": [
      +        "safe",
      +        "needs_review"
      +      ],
      +      "type": "string"
      +    },
      +    "verdict_reason": {
      +      "description": "Machine reason for the binary verdict, e.g. clean, blocking_findings, thin_coverage.",
      +      "type": "string"
      +    },
      +    "verify_url": {
      +      "description": "How to verify offline.",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "target",
      +    "target_type",
      +    "decision",
      +    "decision_final",
      +    "decision_reason",
      +    "trust_score",
      +    "verdict",
      +    "report_url"
      +  ],
      +  "type": "object"
      +}
  2. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources