{"id":"2f580464-db4e-4c96-9e11-d8c5b895e8e6","entityType":"agent","slug":"clawhub-poteshniy-agenttrust-scanner","name":"AgentTrust — Security Scanner for AI Skills","canonicalUrl":"https://www.xpersona.co/agent/clawhub-poteshniy-agenttrust-scanner","canonicalPath":"/agent/clawhub-poteshniy-agenttrust-scanner","generatedAt":"2026-10-10T07:53:39.549Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":null},"description":"Scan AI agent skills for malware, prompt injection, data exfiltration, and 47 other security threats. JWS-signed ACT/HALT receipts. x402-native, no API keys, no accounts. MCP manifest scanning.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17aeqzzfhw3z8bjbdcjbzdz9985ht06:agenttrust-scanner","sourceUrl":"https://clawhub.ai/poteshniy/agenttrust-scanner","homepage":"https://clawhub.ai/poteshniy/skills/agenttrust-scanner","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/poteshniy/agenttrust-scanner","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/poteshniy/skills/agenttrust-scanner","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AgentTrust — Security Scanner for AI Skills technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":null},"stars":null,"forks":null,"downloads":1723,"packageName":null,"latestVersion":"1.4.1","tractionLabel":"1.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:40:58.353Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T03:40:58.354Z","lastCrawledAt":"2026-10-10T03:40:58.353Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T03:40:58.353Z","lastVerifiedAt":null,"highlights":[{"version":"1.4.1","createdAt":"2026-09-17T09:51:52.672Z","changelog":"AgentTrust Scanner 1.4.1 introduces stricter privacy and consent requirements for all submissions. - Enhanced privacy notice: Explicitly states that content is sent outside the local machine, including for free scans. - Consent required: The agent must get explicit approval from users before sending any data, and redact sensitive information by default. - Revised instructions: Clarify to always disclose outbound submissions, avoid uploading secrets, and prefer local summarization for sensitive material. - MCP server install command now uses a pinned package version (@1.0.1) and removes automatic approval flags (no -y). - Removed file: skill-card.md.","fileCount":3,"zipByteSize":4155},{"version":"1.4.0","createdAt":"2026-06-25T19:07:55.314Z","changelog":"- Updated to support IETF draft-krausz-verification-state-01, adding compatibility with AgentOracle as a co-signer. - Introduced composed receipts: two-issuer JWS envelopes (AgentTrust + AgentOracle, Phase 1 live). - Added /compose and /sign endpoints for multi-signer JWS workflows and receipt composition. - Expanded instructions with MCP server install guidance for Claude Desktop, Cursor, and Windsurf. - Minor update: Removed skill-card.md file.","fileCount":3,"zipByteSize":3663},{"version":"1.3.0","createdAt":"2026-06-08T21:19:57.604Z","changelog":"**Major update with expanded scanning, MCP support, and JWS-signed results:** - Added MCP manifest scanning for tool poisoning, shadowing, hidden unicode, and rug pull detection. - Introduced unified trust gate endpoint for combined skill, MCP, and endpoint reputation checks with signed receipts. - All scan responses now include cryptographically signed ACT/HALT (JWS) receipts compliant with draft-krausz-verification-state-00. - Expanded threat detection rules to cover 47+ patterns; full MCP manifest scan now covers 50 rules. - Updated instructions, endpoint details, and removed outdated SKILL.md documentation file.","fileCount":3,"zipByteSize":3194},{"version":"1.2.1","createdAt":"2026-05-25T19:02:58.097Z","changelog":"- Improved description clarifying that AgentTrust uses 40 threat rules across 12 categories and is a real API, not prompt-based. - Highlights new features: integrity hash verification, endpoint reputation checks, on-chain stats from CDP Bazaar, and trust badge SVGs for x402 providers. - No functional or endpoint changes; usage and pricing remain the same. - Documentation updates for better clarity and emphasis on unique capabilities.","fileCount":3,"zipByteSize":2728},{"version":"1.2.0","createdAt":"2026-05-25T18:44:13.210Z","changelog":"v1.2.0: Added endpoint reputation checker (GET /v1/reputation) and SVG trust badge (GET /v1/badge) — both free, no wallet required.","fileCount":2,"zipByteSize":1512},{"version":"1.1.3","createdAt":"2026-05-25T17:33:38.725Z","changelog":"v1.1.3: Added scan result caching — repeated scans of identical content return cached results instantly.","fileCount":2,"zipByteSize":1305},{"version":"1.1.2","createdAt":"2026-05-06T19:53:39.766Z","changelog":"Added explicit user approval requirements before paid endpoints, documented wallet/payment requirements, and added privacy notice about content submission.","fileCount":2,"zipByteSize":1242},{"version":"1.1.1","createdAt":"2026-05-04T16:45:22.245Z","changelog":"Removed threat pattern examples from instructions to reduce false positive detection. Description updated for clarity.","fileCount":2,"zipByteSize":1060}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17aeqzzfhw3z8bjbdcjbzdz9985ht06:agenttrust-scanner","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17aeqzzfhw3z8bjbdcjbzdz9985ht06:agenttrust-scanner` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/poteshniy/agenttrust-scanner before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:53:39.548Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":null},"readme":"Skill: AgentTrust — Security Scanner for AI Skills\n\nOwner: poteshniy\n\nSummary: Scan AI agent skills for malware, prompt injection, data exfiltration, and 47 other security threats. JWS-signed ACT/HALT receipts. x402-native, no API keys, no accounts. MCP manifest scanning.\n\nTags: latest:1.4.1, mcp:1.0.0, openclaw:1.0.0, scanner:1.0.0, security:1.0.0, trust:1.0.0, x402:1.0.0\n\nVersion history:\n\nv1.4.1 | 2026-09-17T09:51:52.672Z | user\n\nAgentTrust Scanner 1.4.1 introduces stricter privacy and consent requirements for all submissions.\n\n- Enhanced privacy notice: Explicitly states that content is sent outside the local machine, including for free scans.\n- Consent required: The agent must get explicit approval from users before sending any data, and redact sensitive information by default.\n- Revised instructions: Clarify to always disclose outbound submissions, avoid uploading secrets, and prefer local summarization for sensitive material.\n- MCP server install command now uses a pinned package version (@1.0.1) and removes automatic approval flags (no -y).\n- Removed file: skill-card.md.\n\nv1.4.0 | 2026-06-25T19:07:55.314Z | user\n\n- Updated to support IETF draft-krausz-verification-state-01, adding compatibility with AgentOracle as a co-signer.\n- Introduced composed receipts: two-issuer JWS envelopes (AgentTrust + AgentOracle, Phase 1 live).\n- Added /compose and /sign endpoints for multi-signer JWS workflows and receipt composition.\n- Expanded instructions with MCP server install guidance for Claude Desktop, Cursor, and Windsurf.\n- Minor update: Removed skill-card.md file.\n\nv1.3.0 | 2026-06-08T21:19:57.604Z | user\n\n**Major update with expanded scanning, MCP support, and JWS-signed results:**\n\n- Added MCP manifest scanning for tool poisoning, shadowing, hidden unicode, and rug pull detection.\n- Introduced unified trust gate endpoint for combined skill, MCP, and endpoint reputation checks with signed receipts.\n- All scan responses now include cryptographically signed ACT/HALT (JWS) receipts compliant with draft-krausz-verification-state-00.\n- Expanded threat detection rules to cover 47+ patterns; full MCP manifest scan now covers 50 rules.\n- Updated instructions, endpoint details, and removed outdated SKILL.md documentation file.\n\nv1.2.1 | 2026-05-25T19:02:58.097Z | user\n\n- Improved description clarifying that AgentTrust uses 40 threat rules across 12 categories and is a real API, not prompt-based.\n- Highlights new features: integrity hash verification, endpoint reputation checks, on-chain stats from CDP Bazaar, and trust badge SVGs for x402 providers.\n- No functional or endpoint changes; usage and pricing remain the same.\n- Documentation updates for better clarity and emphasis on unique capabilities.\n\nv1.2.0 | 2026-05-25T18:44:13.210Z | user\n\nv1.2.0: Added endpoint reputation checker (GET /v1/reputation) and SVG trust badge (GET /v1/badge) — both free, no wallet required.\n\nv1.1.3 | 2026-05-25T17:33:38.725Z | user\n\nv1.1.3: Added scan result caching — repeated scans of identical content return cached results instantly.\n\nv1.1.2 | 2026-05-06T19:53:39.766Z | user\n\nAdded explicit user approval requirements before paid endpoints, documented wallet/payment requirements, and added privacy notice about content submission.\n\nv1.1.1 | 2026-05-04T16:45:22.245Z | user\n\nRemoved threat pattern examples from instructions to reduce false positive detection. Description updated for clarity.\n\nv1.0.1 | 2026-04-25T11:28:29.641Z | user\n\n- Added a free scan option for skills up to 50 lines, checking 5 rules and returning the top 3 findings.\n- Updated full scan endpoint to clarify it checks 40 rules and now also returns a hash.\n- Revised instructions to highlight the availability of a free tier and requirement-free scanning.\n- Clarified payment info and feature details for each scanning and verification endpoint.\n\nv1.0.0 | 2026-04-25T11:06:33.363Z | user\n\nInitial release — 40 security rules, 4 endpoints, x402 native\n\nArchive index:\n\nArchive v1.4.1: 3 files, 4155 bytes\n\nFiles: skill-card.md (2721b), SKILL.md (5908b), _meta.json (137b)\n\nFile v1.4.1:SKILL.md\n\n# AgentTrust\n## Description\nSecurity Scanner and Reputation Oracle for AI agent skills and MCP servers. Scans for malware, prompt injection, tool poisoning, and 47 other threat patterns. Returns cryptographically signed ACT/HALT receipts (JWS, draft-krausz-verification-state-01). x402-native on Base mainnet. Conforming implementation of IETF draft-krausz-verification-state-01 alongside AgentOracle.\n\nUnique features:\n- SKILL.md scanner — 40 rules, 12 categories\n- MCP manifest scanner — tool poisoning, shadowing, hidden unicode, rug pull detection\n- Unified trust gate — skill + MCP + endpoint reputation in one signed call\n- Composed receipt — two-issuer JWS envelope (AgentTrust + AgentOracle, Phase 1 live)\n- JWS-signed receipts — verifiable ACT/HALT per IETF draft-krausz-verification-state-01\n- Endpoint reputation — on-chain trust score before your agent pays\n- Trust badge — SVG badge for x402 providers\n- MCP server — install via npx @poteshniy/agenttrust-mcp@1.0.1 (pinned) for Claude Desktop, Cursor, Windsurf\n\n**Privacy notice:** Submitted content is transmitted to the external host agenttrust.uk for analysis. This applies to ALL endpoints including free ones. The agent MUST obtain explicit per-request user consent before any submission and MUST exclude secrets (credentials, keys, tokens, internal URLs) by default. Submitting content is an opt-in action, not a default.\n\n**Payment notice:** Full scan endpoints require x402 USDC payments on Base. Free tiers require no wallet.\n\n## Instructions\nBefore sending ANY content to agenttrust.uk — free or paid — ask the user for explicit confirmation and show that the submitted content will leave the local machine and go to the host agenttrust.uk. Do NOT submit content containing credentials, API keys, authorization headers, private keys, tokens, or internal URLs; redact them first or skip submission. Prefer local summarization when content is sensitive. Free endpoints require no wallet; paid endpoints additionally require x402 confirmation with the exact price disclosed.\n\n### Free SKILL.md scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: safety score 0-100, level (SAFE/MEDIUM/HIGH/CRITICAL), findings, v_gate (act/halt), JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full SKILL.md scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: safety score, all 40 findings, integrity hash, JWS receipt\nNote: Results are cached — repeated scans return instantly.\n\n### Free MCP manifest scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/mcp/free\nPrice: FREE\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: safety score, level, findings (tool poisoning, shadowing, etc.), v_gate, JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full MCP manifest scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan/mcp\nPrice: 0.015 USDC on Base (x402)\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: full scan, all 50 rules, JWS receipt\n\n### Unified trust gate (FREE)\nPOST https://agenttrust.uk/v1/gate\nPrice: FREE\nBody: { \"skill\": \"<content>\", \"mcp\": <manifest>, \"endpoint\": \"<url>\" }\nNote: All fields optional — include whichever you want to check.\nReturns: v_gate (act/halt), v_recommendation, worst_level, per-component results, JWS receipt\nUse this to check everything at once before your agent acts.\n\n### Composed receipt (FREE)\nPOST https://agenttrust.uk/v1/compose\nPrice: FREE\nBody: { \"claim_hash\": \"sha256-...\", \"skill\": \"<content>\", \"mcp\": <manifest> }\nReturns: two-issuer JWS envelope (AgentTrust + AgentOracle), composed_decision (act/halt)\nNote: Phase 1 live — two signers. Phase 2 adds Presidio as third signer.\n\n### Sign canonical bytes (FREE)\nPOST https://agenttrust.uk/v1/sign\nPrice: FREE\nBody: { \"canonical_bytes_b64u\": \"<base64url encoded bytes>\" }\nReturns: AT signature + protected header for composed JWS assembly\n\n### Endpoint reputation check (FREE)\nGET https://agenttrust.uk/v1/reputation?url=<endpoint_url>\nPrice: FREE\nReturns: trust score 0-100, badge (TRUSTED/UNVERIFIED/SUSPICIOUS), issues, on-chain stats\n\n### Trust badge (FREE)\nGET https://agenttrust.uk/v1/badge?url=<endpoint_url>\nPrice: FREE\nReturns: SVG badge — embed with <img src=\"https://agenttrust.uk/v1/badge?url=YOUR_ENDPOINT\"/>\n\n### Wallet reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402)\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402)\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402)\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with per-finding remediation guidance\n\n### MCP Server (Claude Desktop / Cursor / Windsurf)\nInstall once and use all tools directly in your AI client:\nnpx @poteshniy/agenttrust-mcp@1.0.1\n\nConfig:\n{\"mcpServers\":{\"agenttrust\":{\"command\":\"npx\",\"args\":[\"@poteshniy/agenttrust-mcp@1.0.1\"]}}}\n\nThe package version is pinned intentionally. Verify the package (version, publisher, integrity) before changing the pin. Do not add `-y` — package acquisition should not be silently approved.\n\n### JWS Receipt Verification\nAll scan responses include a signed receipt field. Verify with:\nJWKS: https://agenttrust.uk/.well-known/jwks.json\nMapping: https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md\nSpec: https://datatracker.ietf.org/doc/draft-krausz-verification-state/\n\nFile v1.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1789638712672\n}\n\nFile v1.4.1:skill-card.md\n\n## Description:\n\nAgentTrust scans AI agent skills and MCP server manifests for security threats and returns signed ACT/HALT trust receipts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[poteshniy](https://clawhub.ai/user/poteshniy)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to assess SKILL.md files, MCP manifests, endpoint reputation, and wallet trust signals before an agent installs, trusts, or calls external tools. The skill is intended for workflows where users explicitly approve any outbound submission and redact sensitive content first.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Skill or manifest content may be transmitted outside the local machine to agenttrust.uk.\n\nMitigation: Ask for explicit approval before each submission and disclose that the selected content will leave the local environment.\n\nRisk: Submitted content may contain credentials, tokens, internal URLs, or other sensitive material.\n\nMitigation: Redact secrets and internal details by default, skip submission when redaction is not sufficient, and prefer local summarization for sensitive material.\n\nRisk: Paid endpoints may incur x402 USDC charges on Base.\n\nMitigation: Confirm the exact cost with the user before using any paid endpoint.\n\nRisk: Installing the MCP server fetches an npm package.\n\nMitigation: Verify the pinned package version, publisher, and integrity before adding the MCP server configuration.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/poteshniy/skills/agenttrust-scanner)\n- [AgentTrust service host](https://agenttrust.uk)\n- [AgentTrust JWKS](https://agenttrust.uk/.well-known/jwks.json)\n- [IETF Verification State draft](https://datatracker.ietf.org/doc/draft-krausz-verification-state/)\n- [AgentTrust receipt mapping](https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with endpoint descriptions, shell commands, JSON configuration, and API request examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit per-request consent before transmitting content to agenttrust.uk; paid endpoints require explicit x402 USDC cost confirmation.]\n\n## Skill Version(s):\n\n1.4.1 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.4.0: 3 files, 3663 bytes\n\nFiles: skill-card.md (2466b), SKILL.md (5051b), _meta.json (137b)\n\nFile v1.4.0:SKILL.md\n\n# AgentTrust\n## Description\nSecurity Scanner and Reputation Oracle for AI agent skills and MCP servers. Scans for malware, prompt injection, tool poisoning, and 47 other threat patterns. Returns cryptographically signed ACT/HALT receipts (JWS, draft-krausz-verification-state-01). x402-native on Base mainnet. Conforming implementation of IETF draft-krausz-verification-state-01 alongside AgentOracle.\n\nUnique features:\n- SKILL.md scanner — 40 rules, 12 categories\n- MCP manifest scanner — tool poisoning, shadowing, hidden unicode, rug pull detection\n- Unified trust gate — skill + MCP + endpoint reputation in one signed call\n- Composed receipt — two-issuer JWS envelope (AgentTrust + AgentOracle, Phase 1 live)\n- JWS-signed receipts — verifiable ACT/HALT per IETF draft-krausz-verification-state-01\n- Endpoint reputation — on-chain trust score before your agent pays\n- Trust badge — SVG badge for x402 providers\n- MCP server — install via npx @poteshniy/agenttrust-mcp for Claude Desktop, Cursor, Windsurf\n\n**Privacy notice:** Submitted content is sent to agenttrust.uk for analysis. Only submit content you are comfortable sharing.\n\n**Payment notice:** Full scan endpoints require x402 USDC payments on Base. Free tiers require no wallet.\n\n## Instructions\nAlways try free endpoints first. Before using any paid endpoint, ask the user for explicit confirmation and disclose the exact price.\n\n### Free SKILL.md scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: safety score 0-100, level (SAFE/MEDIUM/HIGH/CRITICAL), findings, v_gate (act/halt), JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full SKILL.md scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: safety score, all 40 findings, integrity hash, JWS receipt\nNote: Results are cached — repeated scans return instantly.\n\n### Free MCP manifest scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/mcp/free\nPrice: FREE\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: safety score, level, findings (tool poisoning, shadowing, etc.), v_gate, JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full MCP manifest scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan/mcp\nPrice: 0.015 USDC on Base (x402)\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: full scan, all 50 rules, JWS receipt\n\n### Unified trust gate (FREE)\nPOST https://agenttrust.uk/v1/gate\nPrice: FREE\nBody: { \"skill\": \"<content>\", \"mcp\": <manifest>, \"endpoint\": \"<url>\" }\nNote: All fields optional — include whichever you want to check.\nReturns: v_gate (act/halt), v_recommendation, worst_level, per-component results, JWS receipt\nUse this to check everything at once before your agent acts.\n\n### Composed receipt (FREE)\nPOST https://agenttrust.uk/v1/compose\nPrice: FREE\nBody: { \"claim_hash\": \"sha256-...\", \"skill\": \"<content>\", \"mcp\": <manifest> }\nReturns: two-issuer JWS envelope (AgentTrust + AgentOracle), composed_decision (act/halt)\nNote: Phase 1 live — two signers. Phase 2 adds Presidio as third signer.\n\n### Sign canonical bytes (FREE)\nPOST https://agenttrust.uk/v1/sign\nPrice: FREE\nBody: { \"canonical_bytes_b64u\": \"<base64url encoded bytes>\" }\nReturns: AT signature + protected header for composed JWS assembly\n\n### Endpoint reputation check (FREE)\nGET https://agenttrust.uk/v1/reputation?url=<endpoint_url>\nPrice: FREE\nReturns: trust score 0-100, badge (TRUSTED/UNVERIFIED/SUSPICIOUS), issues, on-chain stats\n\n### Trust badge (FREE)\nGET https://agenttrust.uk/v1/badge?url=<endpoint_url>\nPrice: FREE\nReturns: SVG badge — embed with <img src=\"https://agenttrust.uk/v1/badge?url=YOUR_ENDPOINT\"/>\n\n### Wallet reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402)\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402)\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402)\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with per-finding remediation guidance\n\n### MCP Server (Claude Desktop / Cursor / Windsurf)\nInstall once and use all tools directly in your AI client:\nnpx @poteshniy/agenttrust-mcp\n\nConfig:\n{\"mcpServers\":{\"agenttrust\":{\"command\":\"npx\",\"args\":[\"-y\",\"@poteshniy/agenttrust-mcp\"]}}}\n\n### JWS Receipt Verification\nAll scan responses include a signed receipt field. Verify with:\nJWKS: https://agenttrust.uk/.well-known/jwks.json\nMapping: https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md\nSpec: https://datatracker.ietf.org/doc/draft-krausz-verification-state/\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1782414475314\n}\n\nFile v1.4.0:skill-card.md\n\n## Description:\n\nAgentTrust scans AI agent skills and MCP server manifests for malware, prompt injection, data exfiltration, tool poisoning, and related security threats, returning signed ACT/HALT receipts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[poteshniy](https://clawhub.ai/user/poteshniy)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to scan AI skills, MCP manifests, endpoints, and wallet reputations before allowing an agent to act or pay. It helps agents obtain security findings, reputation signals, and JWS-signed ACT/HALT receipts from AgentTrust endpoints.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The MCP setup uses an unpinned external package as a persistent AI-client tool.\n\nMitigation: Review the MCP package, scope its permissions in the AI client, and pin a known version before installation.\n\nRisk: Submitted skill content, manifests, endpoint URLs, and wallet addresses are sent to AgentTrust for analysis.\n\nMitigation: Submit only content approved for sharing with AgentTrust and avoid sending sensitive or confidential material unless authorized.\n\nRisk: Some scan, wallet reputation, verification, and report endpoints require x402 USDC payments.\n\nMitigation: Use free endpoints first and approve paid calls only after confirming the exact endpoint, price, and purpose.\n\n## Reference(s):\n\n- [AgentTrust ClawHub listing](https://clawhub.ai/poteshniy/skills/agenttrust-scanner)\n- [IETF draft-krausz-verification-state](https://datatracker.ietf.org/doc/draft-krausz-verification-state/)\n- [AgentTrust JWKS](https://agenttrust.uk/.well-known/jwks.json)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with endpoint descriptions, JSON request examples, shell commands, and MCP configuration snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May direct the agent to obtain JSON scan responses, reputation results, trust badges, and JWS receipts from AgentTrust endpoints.]\n\n## Skill Version(s):\n\n1.4.0 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.3.0: 3 files, 3194 bytes\n\nFiles: skill-card.md (2334b), SKILL.md (4003b), _meta.json (137b)\n\nFile v1.3.0:SKILL.md\n\n# AgentTrust\n## Description\nSecurity Scanner and Reputation Oracle for AI agent skills and MCP servers. Scans for malware, prompt injection, tool poisoning, and 47 other threat patterns. Returns cryptographically signed ACT/HALT receipts (JWS, draft-krausz-verification-state-00). x402-native on Base mainnet.\n\nUnique features:\n- SKILL.md scanner — 40 rules, 12 categories\n- MCP manifest scanner — tool poisoning, shadowing, hidden unicode, rug pull detection\n- Unified trust gate — skill + MCP + endpoint reputation in one signed call\n- JWS-signed receipts — verifiable ACT/HALT per IETF draft-krausz-verification-state-00\n- Endpoint reputation — on-chain trust score before your agent pays\n- Trust badge — SVG badge for x402 providers\n\n**Privacy notice:** Submitted content is sent to agenttrust.uk for analysis. Only submit content you are comfortable sharing.\n\n**Payment notice:** Full scan endpoints require x402 USDC payments on Base. Free tiers require no wallet.\n\n## Instructions\nAlways try free endpoints first. Before using any paid endpoint, ask the user for explicit confirmation and disclose the exact price.\n\n### Free SKILL.md scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: safety score 0-100, level (SAFE/MEDIUM/HIGH/CRITICAL), findings, v_gate (act/halt), JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full SKILL.md scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: safety score, all 40 findings, integrity hash, JWS receipt\nNote: Results are cached — repeated scans return instantly.\n\n### Free MCP manifest scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/mcp/free\nPrice: FREE\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: safety score, level, findings (tool poisoning, shadowing, etc.), v_gate, JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full MCP manifest scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan/mcp\nPrice: 0.015 USDC on Base (x402)\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: full scan, all 50 rules, JWS receipt\n\n### Unified trust gate (FREE)\nPOST https://agenttrust.uk/v1/gate\nPrice: FREE\nBody: { \"skill\": \"<content>\", \"mcp\": <manifest>, \"endpoint\": \"<url>\" }\nNote: All fields optional — include whichever you want to check.\nReturns: v_gate (act/halt), v_recommendation, worst_level, per-component results, JWS receipt\nUse this to check everything at once before your agent acts.\n\n### Endpoint reputation check (FREE)\nGET https://agenttrust.uk/v1/reputation?url=<endpoint_url>\nPrice: FREE\nReturns: trust score 0-100, badge (TRUSTED/UNVERIFIED/SUSPICIOUS), issues, on-chain stats\n\n### Trust badge (FREE)\nGET https://agenttrust.uk/v1/badge?url=<endpoint_url>\nPrice: FREE\nReturns: SVG badge — embed with <img src=\"https://agenttrust.uk/v1/badge?url=YOUR_ENDPOINT\"/>\n\n### Wallet reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402)\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402)\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402)\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with per-finding remediation guidance\n\n### JWS Receipt Verification\nAll scan responses include a signed receipt field. Verify with:\nJWKS: https://agenttrust.uk/.well-known/jwks.json\nMapping: https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md\nSpec: https://datatracker.ietf.org/doc/draft-krausz-verification-state/\n\nFile v1.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1780953597604\n}\n\nFile v1.3.0:skill-card.md\n\n## Description: <br>\nAgentTrust helps agents submit selected skill, MCP manifest, endpoint, wallet, or hash data to a security scanning and reputation service for malware, injection, tool-poisoning, integrity, and trust checks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[poteshniy](https://clawhub.ai/user/poteshniy) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to check AI skills, MCP server manifests, endpoints, wallet addresses, and content hashes before allowing an agent to act, pay, or trust an external capability. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User-selected skill content, MCP manifests, endpoint URLs, hashes, or wallet addresses may be submitted to an external service. <br>\nMitigation: Submit only content the user is comfortable sending to agenttrust.uk, and prefer free endpoints for initial checks. <br>\nRisk: Some endpoints require x402 USDC payments on Base. <br>\nMitigation: Ask for explicit user approval before paid requests and disclose the exact price and submitted content. <br>\n\n\n## Reference(s): <br>\n- [AgentTrust ClawHub listing](https://clawhub.ai/poteshniy/agenttrust-scanner) <br>\n- [AgentTrust JWS key set](https://agenttrust.uk/.well-known/jwks.json) <br>\n- [AgentTrust receipt mapping](https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md) <br>\n- [Verification State IETF draft](https://datatracker.ietf.org/doc/draft-krausz-verification-state/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration, text, markdown] <br>\n**Output Format:** [Markdown instructions with HTTP endpoint details and request/response descriptions] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide users through free or paid external scans and signed receipt verification.] <br>\n\n## Skill Version(s): <br>\n1.3.0 (source: server-resolved release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.2.1: 3 files, 2728 bytes\n\nFiles: skill-card.md (2087b), SKILL.md (3106b), _meta.json (137b)\n\nFile v1.2.1:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills. Unlike prompt-based scanners, AgentTrust is a real API with 40 threat rules across 12 categories — backed by x402 payments on Base mainnet.\n\nUnique features:\n- Integrity hash — verify a skill hasn't changed since last scan\n- Endpoint reputation — check any x402 API before your agent pays\n- On-chain stats — real CDP Bazaar data on calls and payers\n- Trust badge — SVG badge for x402 providers to embed on their sites\n\n**Privacy notice:** Submitted skill content is sent to agenttrust.uk for analysis.\nOnly submit content you are comfortable sharing with this service.\n\n**Payment notice:** Full scan, trust, verify, and report endpoints require\nx402 USDC payments on Base network. A funded wallet is required for paid features.\nThe free endpoint requires no payment or wallet.\n\nFree tier available — no wallet required.\n\n## Instructions\n\nBefore using any paid endpoint, always ask the user for explicit confirmation\nand disclose the exact price. Prefer the free scan unless the user requests\na paid full scan.\n\n### Free scan (no payment, no wallet required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: risk score 0-100, safety level, top findings\nNote: Always try the free scan first. Rate limited to 10 requests/hour per IP.\n\n### Full scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<full skill content>\" }\nReturns: risk score 0-100, safety level, all findings, integrity hash\nNote: Results are cached — repeated scans of identical content return instantly.\nWarning: This sends the full skill content to agenttrust.uk.\n\n### Endpoint reputation check (FREE)\nGET https://agenttrust.uk/v1/reputation?url=<endpoint_url>\nPrice: FREE\nReturns: trust score 0-100, badge (TRUSTED/UNVERIFIED/SUSPICIOUS), issues list, on-chain stats\nNote: Check any x402 endpoint before your agent pays for it.\n\n### Endpoint trust badge (FREE)\nGET https://agenttrust.uk/v1/badge?url=<endpoint_url>\nPrice: FREE\nReturns: SVG badge image for embedding on websites\nNote: Add to your site with <img src=\"https://agenttrust.uk/v1/badge?url=YOUR_ENDPOINT\"/>\n\n### Reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402) — ask user before sending\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402) — ask user before sending\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with recommendations\nWarning: This sends the full skill content to agenttrust.uk.\n\nFile v1.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1779735778097\n}\n\nFile v1.2.1:skill-card.md\n\n## Description: <br>\nScan AI skills for malware, prompt injections, data leaks, integrity changes, and x402 endpoint or wallet reputation without API keys or accounts. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[poteshniy](https://clawhub.ai/user/poteshniy) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use AgentTrust to scan skill content for security risks, verify integrity hashes, and check x402 endpoint or wallet reputation before payment. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Skill content can be shared with the external AgentTrust service during scans. <br>\nMitigation: Use the free scan first and submit only content the user is comfortable sharing with agenttrust.uk. <br>\nRisk: Paid endpoints require wallet-based USDC payments on Base. <br>\nMitigation: Ask for explicit user confirmation and disclose the displayed price before invoking paid endpoints. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/poteshniy/agenttrust-scanner) <br>\n- [AgentTrust free scan endpoint](https://agenttrust.uk/v1/scan/free) <br>\n- [AgentTrust endpoint reputation check](https://agenttrust.uk/v1/reputation?url=<endpoint_url>) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, guidance] <br>\n**Output Format:** [Markdown or text summaries of scan results, reputation checks, integrity verification, or audit reports.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include numeric risk and trust scores, findings, SVG badge links, integrity hashes, and recommendations returned by AgentTrust endpoints.] <br>\n\n## Skill Version(s): <br>\n1.2.1 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.2.0: 2 files, 1512 bytes\n\nFiles: SKILL.md (2865b), _meta.json (137b)\n\nFile v1.2.0:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\nAnalyzes OpenClaw SKILL.md files for security risks before installation.\nChecks for threat patterns across 12 categories.\nNow includes x402 endpoint reputation checking and trust badges.\n\n**Privacy notice:** Submitted skill content is sent to agenttrust.uk for analysis.\nOnly submit content you are comfortable sharing with this service.\n\n**Payment notice:** Full scan, trust, verify, and report endpoints require\nx402 USDC payments on Base network. A funded wallet is required for paid features.\nThe free endpoint requires no payment or wallet.\n\nFree tier available — no wallet required.\n\n## Instructions\n\nBefore using any paid endpoint, always ask the user for explicit confirmation\nand disclose the exact price. Prefer the free scan unless the user requests\na paid full scan.\n\n### Free scan (no payment, no wallet required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: risk score 0-100, safety level, top findings\nNote: Always try the free scan first. Rate limited to 10 requests/hour per IP.\n\n### Full scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<full skill content>\" }\nReturns: risk score 0-100, safety level, all findings, integrity hash\nNote: Results are cached — repeated scans of identical content return instantly.\nWarning: This sends the full skill content to agenttrust.uk.\n\n### Endpoint reputation check (FREE)\nGET https://agenttrust.uk/v1/reputation?url=<endpoint_url>\nPrice: FREE\nReturns: trust score 0-100, badge (TRUSTED/UNVERIFIED/SUSPICIOUS), issues list, on-chain stats\nNote: Check any x402 endpoint before your agent pays for it.\n\n### Endpoint trust badge (FREE)\nGET https://agenttrust.uk/v1/badge?url=<endpoint_url>\nPrice: FREE\nReturns: SVG badge image for embedding on websites\nNote: Add to your site with <img src=\"https://agenttrust.uk/v1/badge?url=YOUR_ENDPOINT\"/>\n\n### Reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402) — ask user before sending\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402) — ask user before sending\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with recommendations\nWarning: This sends the full skill content to agenttrust.uk.\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1779734653210\n}\n\nArchive v1.1.3: 2 files, 1305 bytes\n\nFiles: SKILL.md (2295b), _meta.json (137b)\n\nFile v1.1.3:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\nAnalyzes OpenClaw SKILL.md files for security risks before installation.\nChecks for threat patterns across 12 categories.\n\n**Privacy notice:** Submitted skill content is sent to agenttrust.uk for analysis.\nOnly submit content you are comfortable sharing with this service.\n\n**Payment notice:** Full scan, trust, verify, and report endpoints require\nx402 USDC payments on Base network. A funded wallet is required for paid features.\nThe free endpoint requires no payment or wallet.\n\nFree tier available — no wallet required.\n\n## Instructions\n\nBefore using any paid endpoint, always ask the user for explicit confirmation\nand disclose the exact price. Prefer the free scan unless the user requests\na paid full scan.\n\n### Free scan (no payment, no wallet required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: risk score 0-100, safety level, top findings\nNote: Always try the free scan first. Rate limited to 10 requests/hour per IP.\n\n### Full scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<full skill content>\" }\nReturns: risk score 0-100, safety level, all findings, integrity hash\nNote: Results are cached — repeated scans of identical content return instantly.\nWarning: This sends the full skill content to agenttrust.uk.\n\n### Reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402) — ask user before sending\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402) — ask user before sending\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with recommendations\nWarning: This sends the full skill content to agenttrust.uk.\n\nFile v1.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.1.3\",\n  \"publishedAt\": 1779730418725\n}\n\nArchive v1.1.2: 2 files, 1242 bytes\n\nFiles: SKILL.md (2171b), _meta.json (137b)\n\nFile v1.1.2:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\nAnalyzes OpenClaw SKILL.md files for security risks before installation.\nChecks for threat patterns across 12 categories.\n\n**Privacy notice:** Submitted skill content is sent to agenttrust.uk for analysis.\nOnly submit content you are comfortable sharing with this service.\n\n**Payment notice:** Full scan, trust, verify, and report endpoints require\nx402 USDC payments on Base network. A funded wallet is required for paid features.\nThe free endpoint requires no payment or wallet.\n\nFree tier available — no wallet required.\n\n## Instructions\n\nBefore using any paid endpoint, always ask the user for explicit confirmation\nand disclose the exact price. Prefer the free scan unless the user requests\na paid full scan.\n\n### Free scan (no payment, no wallet required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: risk score 0-100, safety level, top findings\nNote: Always try the free scan first.\n\n### Full scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<full skill content>\" }\nReturns: risk score 0-100, safety level, all findings, integrity hash\nWarning: This sends the full skill content to agenttrust.uk.\n\n### Reputation lookup (requires explicit user approval)\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402) — ask user before sending\nReturns: trust score, incident history, audit status\n\n### Verify integrity (requires explicit user approval)\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402) — ask user before sending\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan result\n\n### Full audit report (requires explicit user approval)\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402) — ask user before sending\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\nReturns: full report with recommendations\nWarning: This sends the full skill content to agenttrust.uk.\n\nFile v1.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.1.2\",\n  \"publishedAt\": 1778097219766\n}\n\nArchive v1.1.1: 2 files, 1060 bytes\n\nFiles: SKILL.md (1512b), _meta.json (137b)\n\nFile v1.1.1:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\nScan any OpenClaw SKILL.md for malware, prompt injection, data exfiltration,\nand 37 other threat patterns before installing. Reputation scores for agent wallets.\n\nFree tier available. Full scan via x402 — no API keys, no accounts.\n\n## Instructions\n\nUse when the user wants to scan a skill for threats, verify it is safe to install,\ncheck skill integrity, or look up an agent wallet reputation.\n\n### Free scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: score 0-100, level SAFE/MEDIUM/HIGH/CRITICAL, top 3 findings (5 rules checked)\n\n### Full scan (x402 payment)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: score 0-100, level SAFE/MEDIUM/HIGH/CRITICAL, all findings (40 rules), hash\n\n### Reputation lookup\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402)\nReturns: score, incidents, audits, verified status\n\n### Verify integrity\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402)\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan level and score\n\n### Full audit report\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402)\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<n>\" }\nReturns: full report with recommendations per finding\n\nFile v1.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1777913122245\n}\n\nArchive v1.0.1: 2 files, 1060 bytes\n\nFiles: SKILL.md (1512b), _meta.json (137b)\n\nFile v1.0.1:SKILL.md\n\n# AgentTrust\n\n## Description\n\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\nScan any OpenClaw SKILL.md for malware, prompt injection, data exfiltration,\nand 37 other threat patterns before installing. Reputation scores for agent wallets.\n\nFree tier available. Full scan via x402 — no API keys, no accounts.\n\n## Instructions\n\nUse when the user wants to scan a skill for threats, verify it is safe to install,\ncheck skill integrity, or look up an agent wallet reputation.\n\n### Free scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: score 0-100, level SAFE/MEDIUM/HIGH/CRITICAL, top 3 findings (5 rules checked)\n\n### Full scan (x402 payment)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: score 0-100, level SAFE/MEDIUM/HIGH/CRITICAL, all findings (40 rules), hash\n\n### Reputation lookup\nGET https://agenttrust.uk/v1/trust/:address\nPrice: 0.010 USDC on Base (x402)\nReturns: score, incidents, audits, verified status\n\n### Verify integrity\nPOST https://agenttrust.uk/v1/verify\nPrice: 0.005 USDC on Base (x402)\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\nReturns: verified true/false, last scan level and score\n\n### Full audit report\nPOST https://agenttrust.uk/v1/report\nPrice: 0.050 USDC on Base (x402)\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<n>\" }\nReturns: full report with recommendations per finding\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1777116509641\n}\n\nArchive v1.0.0: 2 files, 986 bytes\n\nFiles: SKILL.md (1295b), _meta.json (137b)\n\nFile v1.0.0:SKILL.md\n\n# AgentTrust\r\n\r\n## Description\r\n\r\nSecurity Scanner and Reputation Oracle for AI Agent Skills.\r\nScan any OpenClaw SKILL.md for malware, prompt injection, data exfiltration,\r\nand 37 other threat patterns before installing. Reputation scores for agent wallets.\r\nPayment: USDC on Base via x402. No API keys. No accounts.\r\n\r\n## Instructions\r\n\r\nUse when the user wants to scan a skill for threats, verify it is safe to install,\r\ncheck skill integrity, or look up an agent wallet reputation.\r\n\r\n### Scan for threats\r\nPOST https://agenttrust.uk/v1/scan\r\nPrice: 0.015 USDC on Base (x402)\r\nBody: { \"content\": \"<full skill content>\" }\r\nReturns: score 0-100, level SAFE/MEDIUM/HIGH/CRITICAL, findings with line numbers\r\n\r\n### Reputation lookup\r\nGET https://agenttrust.uk/v1/trust/:address\r\nPrice: 0.010 USDC on Base (x402)\r\nReturns: score, incidents, audits, verified status\r\n\r\n### Verify integrity\r\nPOST https://agenttrust.uk/v1/verify\r\nPrice: 0.005 USDC on Base (x402)\r\nBody: { \"hash\": \"<sha256>\" } or { \"content\": \"<skill content>\" }\r\nReturns: verified true/false, last scan level and score\r\n\r\n### Full audit report\r\nPOST https://agenttrust.uk/v1/report\r\nPrice: 0.050 USDC on Base (x402)\r\nBody: { \"content\": \"<skill content>\", \"skill_id\": \"<name>\" }\r\nReturns: full report with recommendations per finding\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777115193363\n}","readmeExcerpt":"Skill: AgentTrust — Security Scanner for AI Skills Owner: poteshniy Summary: Scan AI agent skills for malware, prompt injection, data exfiltration, and 47 other security threats. JWS-signed ACT/HALT receipts. x402-native, no API keys, no accounts. MCP manifest scanning. Tags: latest:1.4.1, mcp:1.0.0, openclaw:1.0.0, scanner:1.0.0, security:1.0.0, trust:1.0.0, x402:1.0.0 Version history: v1.4.1 | 2026-09-17T09:51:52.6","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"# AgentTrust\n## Description\nSecurity Scanner and Reputation Oracle for AI agent skills and MCP servers. Scans for malware, prompt injection, tool poisoning, and 47 other threat patterns. Returns cryptographically signed ACT/HALT receipts (JWS, draft-krausz-verification-state-01). x402-native on Base mainnet. Conforming implementation of IETF draft-krausz-verification-state-01 alongside AgentOracle.\n\nUnique features:\n- SKILL.md scanner — 40 rules, 12 categories\n- MCP manifest scanner — tool poisoning, shadowing, hidden unicode, rug pull detection\n- Unified trust gate — skill + MCP + endpoint reputation in one signed call\n- Composed receipt — two-issuer JWS envelope (AgentTrust + AgentOracle, Phase 1 live)\n- JWS-signed receipts — verifiable ACT/HALT per IETF draft-krausz-verification-state-01\n- Endpoint reputation — on-chain trust score before your agent pays\n- Trust badge — SVG badge for x402 providers\n- MCP server — install via npx @poteshniy/agenttrust-mcp@1.0.1 (pinned) for Claude Desktop, Cursor, Windsurf\n\n**Privacy notice:** Submitted content is transmitted to the external host agenttrust.uk for analysis. This applies to ALL endpoints including free ones. The agent MUST obtain explicit per-request user consent before any submission and MUST exclude secrets (credentials, keys, tokens, internal URLs) by default. Submitting content is an opt-in action, not a default.\n\n**Payment notice:** Full scan endpoints require x402 USDC payments on Base. Free tiers require no wallet.\n\n## Instructions\nBefore sending ANY content to agenttrust.uk — free or paid — ask the user for explicit confirmation and show that the submitted content will leave the local machine and go to the host agenttrust.uk. Do NOT submit content containing credentials, API keys, authorization headers, private keys, tokens, or internal URLs; redact them first or skip submission. Prefer local summarization when content is sensitive. Free endpoints require no wallet; paid endpoints additionally require x402 confirmation with the exact price disclosed.\n\n### Free SKILL.md scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/free\nPrice: FREE\nBody: { \"content\": \"<skill content, max 50 lines>\" }\nReturns: safety score 0-100, level (SAFE/MEDIUM/HIGH/CRITICAL), findings, v_gate (act/halt), JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full SKILL.md scan (requires explicit user approval)\nPOST https://agenttrust.uk/v1/scan\nPrice: 0.015 USDC on Base (x402)\nBody: { \"content\": \"<full skill content>\" }\nReturns: safety score, all 40 findings, integrity hash, JWS receipt\nNote: Results are cached — repeated scans return instantly.\n\n### Free MCP manifest scan (no payment required)\nPOST https://agenttrust.uk/v1/scan/mcp/free\nPrice: FREE\nBody: { \"manifest\": <MCP server manifest JSON> }\nReturns: safety score, level, findings (tool poisoning, shadowing, etc.), v_gate, JWS receipt\nNote: Rate limited to 10 requests/hour per IP.\n\n### Full MCP manifest scan (requires explicit user approv"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7ab822drvwj0k2kk86awrpen85hexk\",\n  \"slug\": \"agenttrust-scanner\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1789638712672\n}"},{"path":"skill-card.md","content":"## Description:\n\nAgentTrust scans AI agent skills and MCP server manifests for security threats and returns signed ACT/HALT trust receipts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[poteshniy](https://clawhub.ai/user/poteshniy)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to assess SKILL.md files, MCP manifests, endpoint reputation, and wallet trust signals before an agent installs, trusts, or calls external tools. The skill is intended for workflows where users explicitly approve any outbound submission and redact sensitive content first.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Skill or manifest content may be transmitted outside the local machine to agenttrust.uk.\n\nMitigation: Ask for explicit approval before each submission and disclose that the selected content will leave the local environment.\n\nRisk: Submitted content may contain credentials, tokens, internal URLs, or other sensitive material.\n\nMitigation: Redact secrets and internal details by default, skip submission when redaction is not sufficient, and prefer local summarization for sensitive material.\n\nRisk: Paid endpoints may incur x402 USDC charges on Base.\n\nMitigation: Confirm the exact cost with the user before using any paid endpoint.\n\nRisk: Installing the MCP server fetches an npm package.\n\nMitigation: Verify the pinned package version, publisher, and integrity before adding the MCP server configuration.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/poteshniy/skills/agenttrust-scanner)\n- [AgentTrust service host](https://agenttrust.uk)\n- [AgentTrust JWKS](https://agenttrust.uk/.well-known/jwks.json)\n- [IETF Verification State draft](https://datatracker.ietf.org/doc/draft-krausz-verification-state/)\n- [AgentTrust receipt mapping](https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with endpoint descriptions, shell commands, JSON configuration, and API request examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit per-request consent before transmitting content to agenttrust.uk; paid endpoints require explicit x402 USDC cost confirmation.]\n\n## Skill Version(s):\n\n1.4.1 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1561,"uniquenessScore":41,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T03:40:58.354Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:53:39.549Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}