Scan a GitHub repo
scan_repoRead-onlyIdempotent
Scan a public GitHub repository with AgentAvow and return whether it is safe for an agent to connect to: one of three answers with its reason (Safe to connect, Review before you connect, or Do not connect), a 0-100 trust score, an adoption score from real usage (stars), the findings behind it (with where and how to fix), and a signed, offline-verifiable attestation. Read-only, no account. Calls the AgentAvow public API at agentavow.com.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| repo | Yes | Repo as 'owner/name' (e.g. 'vercel/next.js'), or just the name when 'owner' is given separately. | |
| force | No | Re-scan now instead of returning the cached verdict (results cache ~1h). Use after the target has changed. | |
| owner | No | Repo owner (optional if 'repo' is already 'owner/name'). |
Output Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| high | No | High findings, static and sandbox. | |
| tier | No | Trust tier for the score (detail, not the headline). | |
| cached | No | Served from the ~1h cache. | |
| signed | No | True when a signed (Ed25519/JWS) attestation backs this. | |
| target | Yes | What was scanned, as given. | |
| install | No | Install command, only when nothing blocks it. | |
| sandbox | No | What the behavioral sandbox observed; null if it does not apply. | |
| verdict | Yes | Binary form of the decision, kept for older clients. | |
| adoption | No | The adoption score: real usage (downloads per week, stars or installs). Never changes the decision. | |
| critical | No | Critical findings, static and sandbox. | |
| decision | Yes | The answer to lead with: safe = Safe to connect, review = Review before you connect, do_not_connect = Do not connect. | |
| incident | No | Known past compromise (context only, never scored). | |
| certified | No | Matches the signed attestation's certified.eligible. | |
| subscores | No | Per-category 0-100 scores behind the trust score. | |
| deprecated | No | The maintainer's deprecation notice, or null. | |
| report_url | Yes | Full report page. | |
| scanned_at | No | When the scan ran (ISO 8601, UTC). | |
| verify_url | No | How to verify offline. | |
| target_type | Yes | github, npm, pypi, crates, docker, hf, or mcp. | |
| trust_score | Yes | Trust score, 0-100. Evidence under the decision. | |
| published_at | No | When that version was published. | |
| top_findings | No | Up to five most important findings. | |
| certified_mark | No | Certified and safe: show the Certified mark. | |
| decision_final | Yes | False while the behavioral sandbox is still running; the decision can still change. | |
| findings_total | No | All findings, every severity. | |
| rescan_pending | No | A fresh scan was started; this is the previous result. | |
| verdict_reason | No | Machine reason for the binary verdict, e.g. clean, blocking_findings, thin_coverage. | |
| decision_reason | Yes | One sentence naming what decided it. | |
| package_version | No | Package version scanned. | |
| report_json_url | No | The full verdict as JSON. | |
| static_findings_total | No | Findings from static analysis only. | |
| advisories_affecting_version | No | Published advisories that affect this version. |