Crawler Summary

agent-discover-scanner answer-first brief

The industry-standard Agentic Identity & Inventory Scanner. Automatically inventory autonomous agents (LangChain, AutoGen, CrewAI, PydanticAI) using static analysis, network heuristics, and eBPF. Foundational tool for AIBOM compliance and AgentOps governance. AgentDiscover Scanner **Open-Source AI Agent Discovery for the Enterprise** $1 $1 $1 $1 *Part of the $1 platform for autonomous AI governance* **Formerly known as agent-discover-scanner** β€” the PyPI package has been renamed to agentdiscover. pip install agent-discover-scanner continues to work and will install agentdiscover automatically. The legacy entry points agent-discover-scanner and agent-discover remain as ali Capability contract not published. No trust telemetry is available yet. 15 GitHub stars reported by the source. Last updated 5/31/2026.

Freshness

Last checked 5/31/2026

Best For

agent-discover-scanner is best for crewai, multi-agent workflows where OpenClaw compatibility matters.

Not Ideal For

Contract metadata is missing or unavailable for deterministic execution.

Evidence Sources Checked

editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack

Claim this agent
Agent DossierGitHubSafety: 75/100

agent-discover-scanner

The industry-standard Agentic Identity & Inventory Scanner. Automatically inventory autonomous agents (LangChain, AutoGen, CrewAI, PydanticAI) using static analysis, network heuristics, and eBPF. Foundational tool for AIBOM compliance and AgentOps governance. AgentDiscover Scanner **Open-Source AI Agent Discovery for the Enterprise** $1 $1 $1 $1 *Part of the $1 platform for autonomous AI governance* **Formerly known as agent-discover-scanner** β€” the PyPI package has been renamed to agentdiscover. pip install agent-discover-scanner continues to work and will install agentdiscover automatically. The legacy entry points agent-discover-scanner and agent-discover remain as ali

OpenClawself-declared

Public facts

4

Change events

0

Artifacts

0

Freshness

May 31, 2026

Verifiededitorial-contentNo verified compatibility signals15 GitHub stars

Capability contract not published. No trust telemetry is available yet. 15 GitHub stars reported by the source. Last updated 5/31/2026.

15 GitHub starsTrust evidence available

Trust score

Unknown

Compatibility

OpenClaw

Freshness

May 31, 2026

Vendor

Defend Ai Tech Inc

Artifacts

0

Benchmarks

0

Last release

Unpublished

Executive Summary

Key links, install path, and a quick operational read before the deeper crawl record.

Verifiededitorial-content

Summary

Capability contract not published. No trust telemetry is available yet. 15 GitHub stars reported by the source. Last updated 5/31/2026.

Setup snapshot

git clone https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner.git
  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence Ledger

Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.

Verifiededitorial-content
Vendor (1)

Vendor

Defend Ai Tech Inc

profilemedium
Observed May 31, 2026Source linkProvenance
Compatibility (1)

Protocol compatibility

OpenClaw

contractmedium
Observed May 31, 2026Source linkProvenance
Adoption (1)

Adoption signal

15 GitHub stars

profilemedium
Observed May 31, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance

Release & Crawl Timeline

Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.

Self-declaredagent-index

Artifacts Archive

Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.

Self-declaredGITHUB OPENCLEW

Extracted files

0

Examples

6

Snippets

0

Languages

python

Executable Examples

text

$ agentdiscover scan-all ./your-repo --duration 10

πŸ” Scanning for autonomous AI agents...

πŸ“‚ Analyzing source code at ./your-repo
🌐 Monitoring live network connections...
   Observing runtime behavior (10s)...
πŸ”— Correlating findings...
βœ“ Correlation complete

πŸ€– Autonomous Agent Inventory

┏━━━━━━━━━━━━━━━━┳━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Classification ┃ Count ┃ Description                                                    ┃
┑━━━━━━━━━━━━━━━━╇━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
β”‚ CONFIRMED      β”‚ 2     β”‚ Active β€” detected in code and observed at runtime              β”‚
β”‚ UNKNOWN        β”‚ 3     β”‚ Code found β€” not yet observed at runtime                       β”‚
β”‚ SHADOW AI      β”‚ 3     β”‚ Known app using AI β€” review for governance                     β”‚
β”‚ ZOMBIE         β”‚ 0     β”‚ Inactive β€” code exists but no recent runtime activity          β”‚
β”‚ GHOST          β”‚ 1     β”‚ ⚠ Critical β€” runtime activity with no source code (ungoverned) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

text

πŸ‘» GHOST AGENT DETECTED
   Workload:    trading-bot (Deployment/default)
   Connected:   api.openai.com β€” LIVE
   SaaS:        openai β€” confirmed active connection
   Source code: None found in scanned repositories
   Owner:       Unknown β€” no deployment record, no code review

πŸ‘» GHOST AGENT DETECTED
   Workload:    shadow-agent (Pod/kube-system)
   Connected:   api.anthropic.com β€” LIVE
   SaaS:        anthropic β€” confirmed  |  gcp β€” active socket
   Blast radius: HIGH (cloud provider access confirmed)
   Source code: None found in scanned repositories
   Owner:       Unknown β€” no deployment record, no code review

text

crewai-agent (CONFIRMED)
  saas_connections:
    anthropic: confirmed  ← active_connection observed
    github:    medium     ← open socket
  risk_flags: [cloud_credentials_present]
  blast_radius: 70/100

bash

# macOS (recommended)
brew install [email protected] osquery pipx
pipx install agentdiscover
pipx ensurepath && source ~/.zshrc   # add ~/.local/bin to PATH

# Linux (Debian/Ubuntu)
sudo apt-get install -y python3 osquery
pip3 install agentdiscover

# Linux (RHEL/Fedora)
sudo dnf install -y python3 osquery
pip3 install agentdiscover

# Windows (PowerShell β€” elevated)
winget install Python.Python.3.12
winget install osquery.osquery
pip install agentdiscover

bash

agentdiscover scan-all ~/projects --duration 30

bash

agentdiscover --version
osquery --version
which agentdiscover   # macOS: should show ~/.local/bin/agentdiscover

# Or use --dry-run to get a complete layer readiness report:
agentdiscover scan-all ~/projects --dry-run

Docs & README

Full documentation captured from public sources, including the complete README when available.

Self-declaredGITHUB OPENCLEW

Docs source

GITHUB OPENCLEW

Editorial quality

ready

The industry-standard Agentic Identity & Inventory Scanner. Automatically inventory autonomous agents (LangChain, AutoGen, CrewAI, PydanticAI) using static analysis, network heuristics, and eBPF. Foundational tool for AIBOM compliance and AgentOps governance. AgentDiscover Scanner **Open-Source AI Agent Discovery for the Enterprise** $1 $1 $1 $1 *Part of the $1 platform for autonomous AI governance* **Formerly known as agent-discover-scanner** β€” the PyPI package has been renamed to agentdiscover. pip install agent-discover-scanner continues to work and will install agentdiscover automatically. The legacy entry points agent-discover-scanner and agent-discover remain as ali

Full README

AgentDiscover Scanner

Open-Source AI Agent Discovery for the Enterprise

License: MIT Python 3.10+ PyPI PRs Welcome

Part of the DefendAI platform for autonomous AI governance

Formerly known as agent-discover-scanner β€” the PyPI package has been renamed to agentdiscover. pip install agent-discover-scanner continues to work and will install agentdiscover automatically. The legacy entry points agent-discover-scanner and agent-discover remain as aliases.


The finding that matters

$ agentdiscover scan-all ./your-repo --duration 10

πŸ” Scanning for autonomous AI agents...

πŸ“‚ Analyzing source code at ./your-repo
🌐 Monitoring live network connections...
   Observing runtime behavior (10s)...
πŸ”— Correlating findings...
βœ“ Correlation complete

πŸ€– Autonomous Agent Inventory

┏━━━━━━━━━━━━━━━━┳━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Classification ┃ Count ┃ Description                                                    ┃
┑━━━━━━━━━━━━━━━━╇━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
β”‚ CONFIRMED      β”‚ 2     β”‚ Active β€” detected in code and observed at runtime              β”‚
β”‚ UNKNOWN        β”‚ 3     β”‚ Code found β€” not yet observed at runtime                       β”‚
β”‚ SHADOW AI      β”‚ 3     β”‚ Known app using AI β€” review for governance                     β”‚
β”‚ ZOMBIE         β”‚ 0     β”‚ Inactive β€” code exists but no recent runtime activity          β”‚
β”‚ GHOST          β”‚ 1     β”‚ ⚠ Critical β€” runtime activity with no source code (ungoverned) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

A GHOST agent is an AI system making real API calls β€” consuming tokens, potentially accessing sensitive data β€” with no corresponding source code, deployment record, or owner. No static analysis tool finds this. No SIEM alerts on it. AgentDiscover Scanner finds it in under 60 seconds by watching the runtime and cross-referencing it against your codebase simultaneously.

Your engineering team thinks they know what AI is running. The GHOST classification is what they don't know.


What makes this different

Most security tools tell you what's in your code. AgentDiscover Scanner tells you what's actually running β€” and crucially, what's running that has no business being there.

πŸ‘» GHOST AGENT DETECTED
   Workload:    trading-bot (Deployment/default)
   Connected:   api.openai.com β€” LIVE
   SaaS:        openai β€” confirmed active connection
   Source code: None found in scanned repositories
   Owner:       Unknown β€” no deployment record, no code review

πŸ‘» GHOST AGENT DETECTED
   Workload:    shadow-agent (Pod/kube-system)
   Connected:   api.anthropic.com β€” LIVE
   SaaS:        anthropic β€” confirmed  |  gcp β€” active socket
   Blast radius: HIGH (cloud provider access confirmed)
   Source code: None found in scanned repositories
   Owner:       Unknown β€” no deployment record, no code review

Every detected agent also carries a SaaS blast radius β€” a live-observed map of which services it's actively connected to, derived from network traffic, not just configuration files:

crewai-agent (CONFIRMED)
  saas_connections:
    anthropic: confirmed  ← active_connection observed
    github:    medium     ← open socket
  risk_flags: [cloud_credentials_present]
  blast_radius: 70/100

confirmed means the connection was live-observed during the scan β€” not inferred from a config file.


Agent classifications

| Classification | What it means | Risk | | ----------------- | ------------------------------------------ | ------------ | | πŸ‘» GHOST | Runtime AI activity β€” no source code found | Critical | | βœ… CONFIRMED | Detected in code AND observed running | High | | ⚠️ UNKNOWN | Found in code, not yet observed at runtime | Medium | | πŸ–₯️ SHADOW AI | Known app using AI without governance | Medium | | ☠️ ZOMBIE | Was active, no longer observed | Low |


What counts as an "agent"

DefendAI classifies AI-capable components, not just top-level orchestrators. Any component that invokes a model, holds a memory buffer, binds a tool, or queries a vector store is an independently governable unit β€” it can exfiltrate data, consume budget, or behave unexpectedly on its own.

This matters because the gap between "we have one AI agent" (what the team believes) and the actual component count is routinely 5–15Γ—.

Example β€” a single LangGraph application with 3 workers:

| # | Component | Why it's tracked | |---|---|---| | 1 | StateGraph | Graph entrypoint; controls execution flow | | 2–4 | Worker agent nodes Γ—3 | Each is an independent LangChain agent | | 5–7 | LLM bindings Γ—3 (one per worker) | Direct model invocations; each has its own token budget | | 8 | Supervisor node | Routes tasks between workers; has its own LLM call | | 9 | LLM binding for supervisor | Additional model invocation with separate prompt | | 10 | Tool node | Executes tool calls on behalf of workers | | 11 | Vector store retriever | RAG component; queries an external embedding store | | 12 | Memory checkpointer | Persists conversation state across turns | | 13 | Prompt templates | Carry system-level instructions that can be injected or drifted | | 14 | Output parser | Transforms model output; can silently drop or alter content | | 15 | Human-in-the-loop interrupt | Pause point that can be bypassed in non-interactive runs |

One application. One developer who says "it's just an AI assistant." Fifteen components that each independently touch a model, a store, or a tool β€” any of which could be ungoverned, GHOST-classified, or carrying a stale permission scope.

Why component-level visibility matters:

  • A worker's LLM binding can be swapped (model drift) without changing the agent node that wraps it.
  • A retriever can be pointed at a new vector store index without redeploying the application.
  • A prompt template lives in a config file, not code β€” static analysis misses it; only runtime observation catches the change.
  • GHOST detection fires at the component level: if worker 2's LLM binding starts calling a different endpoint, the graph-level agent still looks CONFIRMED while that specific binding is GHOST.

agentdiscover reports each component as a separate inventory item so your governance controls can target the right granularity.


Quick start

# macOS (recommended)
brew install [email protected] osquery pipx
pipx install agentdiscover
pipx ensurepath && source ~/.zshrc   # add ~/.local/bin to PATH

# Linux (Debian/Ubuntu)
sudo apt-get install -y python3 osquery
pip3 install agentdiscover

# Linux (RHEL/Fedora)
sudo dnf install -y python3 osquery
pip3 install agentdiscover

# Windows (PowerShell β€” elevated)
winget install Python.Python.3.12
winget install osquery.osquery
pip install agentdiscover

macOS: never use sudo with the installer β€” Homebrew refuses root and osquery silently fails. Use pipx to avoid Python environment conflicts. If agentdiscover is not found after install, run pipx ensurepath and restart your terminal.

Then run your first scan:

agentdiscover scan-all ~/projects --duration 30

To verify all layers are working before your first real scan:

agentdiscover --version
osquery --version
which agentdiscover   # macOS: should show ~/.local/bin/agentdiscover

# Or use --dry-run to get a complete layer readiness report:
agentdiscover scan-all ~/projects --dry-run

To upload results to the DefendAI platform:

agentdiscover scan-all ~/projects \
  --platform \
  --api-key YOUR_API_KEY

What you'll see on your first scan

Running scan-all on a real developer machine (macOS, ~30s observation window):

$ agentdiscover scan-all ~/projects --duration 30

πŸ” Scanning for autonomous AI agents...

πŸ“‚ Analyzing source code at /Users/alice/projects
🌐 Monitoring live network connections...
   Observing runtime behavior (30s)...
πŸ’» Scanning endpoints...

[DETECT] Anthropic connection from Cursor Helper (PID: 61436) β†’ api.anthropic.com:443
[DETECT] OpenAI connection from Microsoft Edge Helper (PID: 4172) β†’ api.openai.com:443

πŸ”— Correlating findings...
βœ“ Correlation complete

⚠ Unverified MCP server: filesystem (Community/Unknown) β€” not from a verified publisher

πŸ€– Autonomous Agent Inventory

┏━━━━━━━━━━━━━━━━┳━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Classification ┃ Count ┃ Description                                                    ┃
┑━━━━━━━━━━━━━━━━╇━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
β”‚ CONFIRMED      β”‚ 1     β”‚ Active β€” detected in code and observed at runtime              β”‚
β”‚ UNKNOWN        β”‚ 2     β”‚ Code found β€” not yet observed at runtime                       β”‚
β”‚ SHADOW AI      β”‚ 4     β”‚ Known app using AI β€” review for governance                     β”‚
β”‚ ZOMBIE         β”‚ 0     β”‚ Inactive β€” code exists but no recent runtime activity          β”‚
β”‚ GHOST          β”‚ 0     β”‚ ⚠ Critical β€” runtime activity with no source code (ungoverned) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Risk Breakdown:
  ● Critical: 0
  ● High: 1
  ● Medium: 2
  ● Low: 4

βœ… Scan complete β€” results saved to defendai-results

All output files land in ./defendai-results/:

| File | Contents | |---|---| | layer1_code.sarif | Code findings in SARIF format (GitHub Security tab ready) | | layer2_network.json | Live network connections observed during scan | | layer3_k8s.jsonl | Kubernetes workload events (if cluster available) | | layer4_endpoint.json | Installed packages, desktop apps, browser AI usage | | agent_inventory.json | Final correlated agent inventory |

For an executive-ready audit bundle (AIBOM + markdown reports):

agentdiscover audit ~/projects --output ./audit-report
# Writes: audit-report/aibom.json, ghost-agents.md, mcp-report.md, summary.md

Common issues

agentdiscover: command not found after pipx install

pipx ensurepath
source ~/.zshrc   # or ~/.bashrc on Linux

If still missing: which agentdiscover should show ~/.local/bin/agentdiscover. If ~/.local/bin is not in $PATH, add it manually.

Layer 2 network monitoring fails on Linux

Layer 2 requires elevated privileges on Linux. Either run with sudo (avoid on macOS) or skip the layer:

sudo agentdiscover scan-all ~/projects --duration 30
# or skip Layer 2:
agentdiscover scan-all ~/projects --skip-layers 2

osquery not installed β€” Layer 4 skipped

Layer 4 is optional. If osquery is not installed, the scan continues with Layers 1–3. To install:

# macOS
brew install osquery
# Linux
sudo apt-get install osquery   # or see https://osquery.io/downloads

Large repo warning β€” scan is slow

If you see ⚠ Large scan path detected: N Python files, point the scanner at a specific project directory rather than your entire home folder:

agentdiscover scan-all ~/projects/my-agent-project --duration 30

Layer 3 Kubernetes not available

If no cluster is reachable, Layer 3 logs a warning and continues. GHOST detection still works via Layer 2 network correlation. To skip Layer 3 explicitly:

agentdiscover scan-all ~/projects --skip-layers 3

Check what layers are ready before scanning

agentdiscover scan-all ~/projects --dry-run

How it works

GHOST detection mechanism

AgentDiscover Scanner runs five detection layers simultaneously and correlates them into a single agent inventory. Each layer sees something the others can't.

| Layer | Name | Technology | Requirements | |---|---|---|---| | 1 | Source code | Python AST + esprima (JS/TS) | None | | 2 | Live network | psutil connection observation | Linux: root/sudo | | 3 | Kubernetes runtime | Tetragon/eBPF events; K8s API fallback | Linux (eBPF); kubectl (K8s API) | | 4 | Endpoint discovery | osquery β€” packages, apps, browser history | osquery (optional) | | 5 | Cloud Audit | AWS CloudTrail, Azure Monitor (stub), GCP Audit Logs (stub) | AWS credentials (boto3) | | 5 | SSE Proxy | Zscaler ZIA web logs, Prisma Access / Cortex Data Lake | Credentials for Zscaler or Prisma |

AgentDiscover detection pipeline

Layer 1 β€” Source code analysis

Static analysis of Python and JavaScript/TypeScript. Detects LangChain, LangGraph, CrewAI, AutoGen, direct OpenAI/Anthropic/Gemini API usage, and any HTTP client targeting LLM endpoints. Handles import aliasing and indirect usage patterns. Generates SARIF output for CI/CD integration.

Layer 2 β€” Live network monitoring

Passive observation of outbound connections to AI providers β€” OpenAI, Anthropic, Google Gemini, Mistral, Cohere, Azure OpenAI, AWS Bedrock, and vector stores. No packet capture. Identifies which process is making each connection, enabling per-agent SaaS attribution.

Real scan output:

[DETECT] Google AI connection from Mail (PID: 776) β†’ generativelanguage.googleapis.com:993
[DETECT] OpenAI connection from Microsoft Edge Helper (PID: 4172) β†’ api.openai.com:443
[DETECT] Anthropic connection from Cursor Helper (PID: 61436) β†’ api.anthropic.com:443
[DETECT] OpenAI connection from OneDrive (PID: 96089) β†’ api.openai.com:443

Layer 5 β€” Cloud Audit (v2.7.0+)

Why Layer 2 misses AWS Bedrock. AWS Bedrock Runtime endpoints rotate across hundreds of generic EC2 IPs with no published CIDR ranges and no stable reverse-DNS pattern. Passive socket monitoring (psutil) can observe the TCP connection but cannot reliably identify it as Bedrock without a complete, continuously-updated IP allowlist β€” which does not exist publicly. On VPC endpoints, traffic stays inside the AWS network and never appears on the host's socket table at all.

Layer 5 β€” Cloud Audit is the enterprise-grade alternative. It queries cloud provider audit logs directly, giving you every AI API call with the caller identity, source IP, model ID, and the HTTP User-Agent the SDK set at call time β€” honest framework attribution (langchain-aws, boto3, amazon-bedrock-agent) that static code analysis can miss.

Provider support matrix:

| Provider | Service | Status | CLI flag | |---|---|---|---| | AWS | Bedrock (CloudTrail) | GA | --cloud-audit | | Azure | Azure OpenAI (Monitor) | Preview stub | --azure-monitor | | GCP | Vertex AI (Cloud Audit Logs) | Preview stub | --gcp-audit |

Required IAM permission (AWS):

{
  "Effect": "Allow",
  "Action": ["cloudtrail:LookupEvents"],
  "Resource": "*"
}

For CloudTrail Lake (near-real-time, ~60s delay instead of 5-15 min):

{
  "Effect": "Allow",
  "Action": [
    "cloudtrail:StartQuery",
    "cloudtrail:GetQueryResults"
  ],
  "Resource": "*"
}

CLI usage:

# Enable Cloud Audit detection (1-hour lookback, us-east-1)
agentdiscover scan-all ~/projects --cloud-audit

# Specify region and longer lookback window
agentdiscover scan-all ~/projects \
  --cloud-audit \
  --cloud-audit-region eu-west-1 \
  --cloud-audit-hours 4

# CloudTrail Lake β€” near-real-time (~60s delay)
agentdiscover scan-all ~/projects \
  --cloud-audit \
  --cloud-audit-lake-arn arn:aws:cloudtrail:us-east-1:123456789012:eventdatastore/YOUR-ARN \
  --cloud-audit-region us-east-1

# Works with audit mode too
agentdiscover audit ~/projects \
  --cloud-audit \
  --cloud-audit-region us-east-1

When Layer 5 findings are merged with Layer 2 network findings, the correlator can promote an agent from UNKNOWN to CONFIRMED even on VPC endpoints where psutil sees nothing. Layer 5 findings are written to layer5_cloud_audit.json in the output directory.

Credential configuration. The scanner uses standard boto3 credential resolution: AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY environment variables, ~/.aws/credentials, or an EC2/ECS/EKS instance role. If no credentials are found, a clear warning is printed and the scan continues without Cloud Audit.

Layer 5 β€” SSE Proxy (v2.8.0+)

Why this matters for enterprise networks. In environments with Secure Service Edge (SSE) proxies such as Zscaler ZIA or Palo Alto Prisma Access, all HTTPS traffic β€” including LLM API calls β€” is intercepted and TLS-inspected by the proxy. Layer 2 (psutil) sees the local IP of the proxy rather than api.openai.com, so it cannot identify LLM traffic. Layer 5 SSE Proxy solves this by querying the proxy's own web transaction logs, which contain the real destination hostname, the source user identity, and an allow/block disposition for every request.

What SSE proxy logs give you that psutil cannot:

  • Real destination hostname β€” even when traffic flows through a zero-trust proxy
  • User identity β€” the [email protected] principal from the proxy's identity provider integration, not just a PID
  • Complete visibility across all machines β€” a single query covers your entire organisation, not just the machine the scanner runs on
  • Block/allow audit trail β€” know which LLM calls your policy blocked, not just which ones succeeded

SSE proxy provider support matrix (v2.8.0):

| Provider | Product | Status | CLI flag | |---|---|---|---| | Zscaler | ZIA (web transaction logs) | GA | --zscaler | | Palo Alto Networks | Prisma Access / Cortex Data Lake | GA | --prisma-access | | Netskope | Security Cloud | Preview stub | (coming soon) |

Zscaler ZIA setup:

Set four environment variables before running:

export ZSCALER_API_KEY="your-api-key"      # from ZIA admin portal β†’ Administration β†’ API Key Management
export ZSCALER_USERNAME="[email protected]"   # auditor or read-only admin role
export ZSCALER_PASSWORD="your-password"
export ZSCALER_TENANT="acme"               # tenant prefix: acme β†’ https://acme.zsapi.net

The scanner uses Zscaler's HMAC-obfuscated session authentication β€” the same algorithm used by the official Zscaler Python SDK. Required role: Auditor (read-only access to web transaction logs).

agentdiscover scan-all ~/projects --zscaler --cloud-audit-hours 4

# Override credentials at runtime (useful in CI):
agentdiscover scan-all ~/projects \
  --zscaler \
  --zscaler-tenant acme \
  --zscaler-api-key "$ZSCALER_API_KEY" \
  --cloud-audit-hours 2

Prisma Access / Cortex Data Lake setup:

export PRISMA_CLIENT_ID="your-client-id"        # OAuth2 client ID from Prisma Access hub
export PRISMA_CLIENT_SECRET="your-secret"
export PRISMA_TENANT_ID="123456789"             # Tenant Service Group (TSG) ID
export PRISMA_REGION="us"                       # us | eu | uk | sg | ca | jp | au
agentdiscover scan-all ~/projects --prisma-access --cloud-audit-hours 4

# Specify region explicitly:
agentdiscover scan-all ~/projects \
  --prisma-access \
  --prisma-region eu \
  --prisma-tenant-id "$PRISMA_TENANT_ID" \
  --cloud-audit-hours 2

Combining SSE Proxy with Cloud Audit:

Both sub-systems of Layer 5 run in parallel with each other and with Layers 1–4. You can enable all of them in a single command:

agentdiscover scan-all ~/projects \
  --cloud-audit \
  --cloud-audit-region us-east-1 \
  --zscaler \
  --prisma-access \
  --cloud-audit-hours 4

SSE proxy findings are written to layer5_sse_proxy.json. The correlator treats them identically to Cloud Audit findings: a code finding (Layer 1) matching an SSE proxy event β†’ CONFIRMED; an SSE proxy event with no code match β†’ GHOST (with process_name set to the proxy's [email protected] identity).

Layer 3 β€” Kubernetes runtime

Kernel-level visibility into pod behavior via Tetragon. Identifies which workloads are actively making AI calls β€” including workloads with no corresponding source code. Works with any CNI. Falls back to Kubernetes API discovery if Tetragon is unavailable.

When Layer 1 (code) and Layer 3 (K8s runtime) both detect the same agent, it becomes CONFIRMED:

Detection Coverage:
┏━━━━━━━━━━━━━━━┳━━━━━━━━┓
┃ Layers        ┃ Agents ┃
┑━━━━━━━━━━━━━━━╇━━━━━━━━┩
β”‚ layer1,layer3 β”‚ 2      β”‚  ← CONFIRMED: seen in code AND running in K8s
β”‚ layer1        β”‚ 3      β”‚  ← UNKNOWN: code found, not yet observed at runtime
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Layer 3 limitations

Layer 3 (eBPF via Tetragon) is Linux-only. On macOS and Windows developer machines, Layer 3 is skipped automatically β€” the scan continues with Layers 1, 2, and 4. The K8s API monitor path works on all platforms and requires only kubectl with cluster read access.

Layer 4 β€” Endpoint discovery

Scans developer machines, CI/CD runners, and workstations via osquery. Finds installed AI packages, desktop AI applications (ChatGPT Desktop, Claude Desktop, Cursor, GitHub Copilot), active connections, browser-based AI usage, and VSCode extensions.

Cross-layer correlation

After all layers run, the correlator builds a unified agent identity. An agent seen in code (Layer 1), confirmed running in K8s (Layer 3), and observed making network calls (Layer 2) is a single correlated identity β€” not three separate findings.

Agents present at runtime with no Layer 1 match become GHOST agents.

SaaS blast radius detection (v2.3.0+)

After correlation, each agent receives a saas_connections profile built from all four layers:

{
  "detected":  ["anthropic", "gcp", "github"],
  "confirmed": ["anthropic"],
  "evidence": {
    "anthropic": ["active_connection", "open_socket"],
    "gcp":       ["open_socket"],
    "github":    ["vscode_extension_detected"]
  },
  "confidence": {
    "anthropic": "confirmed",
    "gcp":       "medium",
    "github":    "medium"
  },
  "has_cloud_provider": true,
  "has_llm_provider":   true
}

High-risk agent detection (v2.4.0+)

The scanner detects autonomous agent platforms that carry systemic security risk by design β€” not misconfigurations, but architecture.

OpenClaw (formerly Clawdbot/Moltbot) is the primary target. It has full filesystem access, terminal execution, email and messaging integration, and runs as a persistent background daemon. CVE-2026-25253 CVSS 8.8. Gartner: "insecure by default." Microsoft: "treat as untrusted code execution."

Detection uses corroborated signals β€” never a single port number:

🚨 HIGH-RISK AGENT CONFIRMED: OpenClaw
   Autonomous agent with system-level access β€” filesystem,
   terminal, email, and messaging integration.
   Capabilities: filesystem, terminal, email, browser, messaging

MCP server detection (v2.4.0+)

MCP (Model Context Protocol) is the integration layer between AI agents and enterprise SaaS. Supported by Claude, ChatGPT, Gemini, Copilot, Cursor, and VS Code.

The scanner detects MCP servers across all AI clients and classifies each by publisher verification:

⚠ Local MCP script detected β€” unknown code with tool access
⚠ Unverified MCP server: filesystem (Community/Unknown) β€” not from a verified publisher
⚠ Unverified MCP server: mcpfw (Unknown) β€” not from a verified publisher

βœ“ Verified: @salesforce/mcp-server (Salesforce official)

Supported clients: Claude Desktop, Cursor, Windsurf, VS Code, Gemini CLI, OpenAI Codex, Continue.dev, Zed, and project-level MCP configs.

Non-developer detection: Financial analysts connecting ChatGPT Teams to Salesforce via UI leave no local config file. The scanner detects this via Layer 2 network traffic β€” the only tool that catches this pattern.

Risk prioritization in reporting (guidance):

  • Unverified MCP server β†’ HIGH
  • MCP filesystem access β†’ HIGH
  • MCP + production environment β†’ CRITICAL
  • OpenClaw + GHOST β†’ CRITICAL

Daemon mode

Run continuously as a background service, updating the agent inventory every 30 seconds:

agentdiscover scan-all ~/projects \
  --daemon \
  --output ~/defendai-results \
  --platform \
  --platform-interval 5    # upload to platform every ~2.5 minutes

Note: --daemon runs until you press Ctrl+C. Use --output ~/defendai-results (or any user-writable path) β€” avoid /var/log/ which requires root. If running as root, ~/projects resolves to root's home directory, not yours. Always run without sudo.

With --platform, the daemon syncs to the DefendAI platform every N correlation cycles (default: every 5 cycles β‰ˆ 2.5 minutes) and always uploads a final snapshot on shutdown.

Linux β€” install as a systemd service:

sudo bash deployment/systemd/install-service.sh ~/projects
systemctl status defendai-scanner

Scanning an additional source repository

The --src-repo flag adds a second codebase to every Layer 1 scan. Findings are merged into layer1_code.sarif alongside the primary scan, so the correlator sees code from both locations in the same run β€” useful when the runtime you're monitoring is served by a separate repo (microservices, shared ML libraries, a vendor repo you don't own locally).

# One-shot: include a remote team's repo in the scan
agentdiscover scan-all ~/projects \
  --src-repo https://github.com/acme/ml-services \
  --duration 30

# Local path β€” no clone step
agentdiscover scan-all ~/projects \
  --src-repo ~/shared/ml-services

In one-shot mode the remote repo is shallow-cloned, scanned, and deleted before the correlator runs.

In daemon mode, pass --src-repo-ttl to control how frequently the additional repo is re-fetched:

agentdiscover scan-all ~/projects \
  --daemon \
  --src-repo https://github.com/acme/ml-services \
  --src-repo-ttl 7200    # re-clone at most once every 2 hours

Auth failures (HTTP 401/403, SSH key rejection) back off exponentially up to 5 minutes and retry automatically β€” the primary scan continues uninterrupted.


Customizing known applications

By default, the scanner classifies common desktop applications (browsers, Office 365, Cursor, Slack, Claude Desktop, etc.) as Shadow AI rather than GHOST when they make AI API calls.

Browser-based AI usage (claude.ai, chatgpt.com, copilot.microsoft.com) is detected via Layer 4 browser history β€” these are classified as Shadow AI automatically. Note that Layer 4 reads the browser's committed history database, not the current active session, so a tab open right now may not appear until the browser flushes its history.

To add your own internal tools:

mkdir -p ~/.defendai
echo "my-internal-ai-tool" >> ~/.defendai/known_apps.txt
echo "company-llm-client" >> ~/.defendai/known_apps.txt

See docs/known-apps-example.txt for the full format.

When connected to the DefendAI platform (--platform flag), the tenant-managed list is downloaded automatically on startup and merged with your local overrides.


DefendAI platform integration

The scanner is the discovery layer. The platform is where discovered agents become governed agents.

agentdiscover scan-all ~/projects \
  --platform \
  --api-key YOUR_KEY \
  --duration 30

When connected to the platform, each scan triggers the correlation engine which builds a living identity map across every machine, every environment, and every scan:

  • Agent identity resolution β€” the same CrewAI agent on a laptop, in staging K8s, and in prod K8s is recognized as one agent at different lifecycle stages
  • Behavioral drift detection β€” agent added has_code_execution=true since last week? That's a signal. Platform tracks it.
  • Cross-machine intelligence β€” agent seen on 3 machines and crossed from dev into prod? Automatic risk escalation.
  • SaaS blast radius β€” platform aggregates confirmed SaaS connections across all scans and computes blast radius score.

After a few scans, the DefendAI platform report shows:

Agent Inventory Report β€” acme-corp
─────────────────────────────────────────────────────────────────────
 shadow-agent    GHOST     CRITICAL   anthropic, github   blast: 85   machines: 3
                           ↑ GHOST seen in production β€” immediate action required

 crewai-agent    SHADOW    MEDIUM     openai              blast: 25   machines: 1
                           ↑ Unreviewed β€” no governance record

 langchain-agent KNOWN     LOW        openai              blast: 15   machines: 1
                           ↑ Approved β€” monitoring active
─────────────────────────────────────────────────────────────────────
 3 agents total Β· 1 critical Β· 1 unreviewed Β· 1 governed

CI/CD integration

GitHub Action (recommended)

The repo ships a reusable composite action. Add it to any workflow with one step β€” no pip install required:

# .github/workflows/agent-scan.yml
name: AI Agent Scan

on: [push, pull_request]

permissions:
  security-events: write   # required to upload SARIF to GitHub Security tab

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - uses: Defend-AI-Tech-Inc/[email protected]
        with:
          path: '.'               # directory to scan (default: .)
          upload-sarif: 'true'    # post findings to GitHub Security tab (default: true)

Findings appear in Security β†’ Code scanning alerts as soon as the workflow runs.

Inputs

| Input | Default | Description | |---|---|---| | path | . | Directory to scan | | output | agent-scan-results.sarif | SARIF output file path | | upload-sarif | true | Upload to GitHub Security tab | | python-version | 3.12 | Python version to use |

Output

| Output | Description | |---|---| | sarif-file | Path to the generated SARIF file |

Note: permissions: security-events: write is required at the job or workflow level for upload-sarif: 'true' to work. If your repo is private and you don't have GitHub Advanced Security, set upload-sarif: 'false' and consume the SARIF artifact directly.

Manual install in CI

- name: Scan for AI agents
  run: |
    pip install agentdiscover
    agentdiscover scan . --format sarif --output results.sarif

- name: Upload SARIF to GitHub Security tab
  uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

For a full-stack scan (all layers, structured output):

- name: Full agent scan
  run: |
    agentdiscover scan-all . \
      --duration 30 \
      --output ./defendai-results \
      --skip-layers 3    # no K8s cluster in CI

Commands

# Full scan (recommended) β€” all layers + correlation
agentdiscover scan-all PATH [OPTIONS]
  --duration/-d SECONDS      Network and K8s monitor observation window [default: 60]
  --output/-o PATH           Output directory for scan results [default: defendai-results]
  --format/-f TEXT           Output format: text|json [default: text]
                               (SARIF output is written to disk by Layer 1 as layer1_code.sarif)
  --layer3-file PATH         Use existing Tetragon JSONL output (skip live Layer 3)
  --skip-layers TEXT         Comma-separated layers to skip, e.g. '3' or '2,3'
  --verbose/-v               Include Layer 3 raw event output
  --daemon                   Run continuously, re-scanning every 30 seconds
  --platform                 Upload results to DefendAI platform after scan
  --api-key TEXT             DefendAI platform API key
  --tenant-token TEXT        DefendAI platform tenant token
  --wawsdb-url TEXT          DefendAI platform base URL [default: https://wauzeway.defendai.ai]
  --platform-interval INT    Upload every N correlation cycles in daemon mode [default: 5]
  --max-log-size INT         Rotate output files at this size in MB [default: 50]
  --max-log-backups INT      Rotated backup files to keep [default: 5]
  --src-repo TEXT            Additional source repo to scan through Layer 1 (local path or URL)
  --src-repo-ttl INT         Daemon: minimum seconds between re-scans of --src-repo [default: 3600]
  --dry-run                  Check layer availability without running a scan

  # Layer 5 β€” Cloud Audit (v2.7.0+)
  --cloud-audit              Enable AWS CloudTrail Bedrock detection
  --cloud-audit-region TEXT  AWS region [default: us-east-1]
  --cloud-audit-hours INT    Lookback window in hours [default: 1 when --cloud-audit set]
  --cloud-audit-lake-arn TEXT  CloudTrail Lake event data store ARN (near-real-time, ~60s delay)
  --azure-monitor            [Preview] Enable Azure Monitor detection
  --gcp-audit                [Preview] Enable GCP Cloud Audit Log detection

  # Layer 5 β€” SSE Proxy (v2.8.0+)
  --zscaler                  Enable Zscaler ZIA web-proxy log detection
  --zscaler-tenant TEXT      Zscaler tenant prefix (overrides ZSCALER_TENANT)
  --zscaler-api-key TEXT     Zscaler API key (overrides ZSCALER_API_KEY)
  --prisma-access            Enable Prisma Access / Cortex Data Lake detection
  --prisma-tenant-id TEXT    Prisma tenant / TSG ID (overrides PRISMA_TENANT_ID)
  --prisma-client-id TEXT    Prisma OAuth2 client ID (overrides PRISMA_CLIENT_ID)
  --prisma-region TEXT       CDL region: us/eu/uk/sg/ca/jp/au (overrides PRISMA_REGION)

# Individual layers
agentdiscover scan PATH              # Layer 1: source code only
agentdiscover deps PATH              # Dependency scanning
agentdiscover monitor                # Layer 2: network monitor only
agentdiscover monitor-k8s            # Layer 3: Kubernetes runtime only
agentdiscover endpoint               # Layer 4: endpoint scan only
agentdiscover correlate              # Correlate existing scan outputs

# Audit mode (v2.5.0+) β€” full report: aibom.json, ghost-agents.md, mcp-report.md
# Accepts all --cloud-audit-* and --zscaler / --prisma-access flags above.
agentdiscover audit PATH [OPTIONS]
  --duration/-d SECONDS      Observation window [default: 60]
  --output/-o PATH           Report output directory [default: defendai-audit]
  --layer3-file PATH         Use existing Tetragon JSONL (skip live Layer 3)
  --platform                 Upload to DefendAI platform
  --api-key TEXT             DefendAI platform API key

# Legacy aliases β€” all three still work
agent-discover-scanner [COMMAND] [OPTIONS]
agent-discover [COMMAND] [OPTIONS]

Detected frameworks and providers

AI frameworks: LangChain, LangGraph, CrewAI, AutoGen, direct HTTP LLM clients

LLM providers: OpenAI, Anthropic, Google Gemini / Google AI, Mistral, Cohere, Azure OpenAI, AWS Bedrock, Groq, DeepSeek

Vector stores: Pinecone, Weaviate, Qdrant, Chroma

SaaS blast radius detection (v2.3.0+): Salesforce, Slack, GitHub, GitLab, Jira, HubSpot, Notion, Airtable, Stripe, Twilio, Snowflake, Databricks, AWS, GCP, Azure, PostgreSQL, Redis, MongoDB


Try the demo

git clone https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner
cd agent-discover-scanner/demo
./setup.sh    # deploys LangChain, CrewAI, and a shadow agent to local Kubernetes
agentdiscover scan-all ./sample-repo --duration 60

Expected output: 2 CONFIRMED agents (crewai-agent, langchain-agent), 1 GHOST agent (shadow-agent β€” runtime activity, no source code).


Requirements

| Capability | Requirement | | ------------------ | -------------------------------------------------------------------------------------------------- | | Code scanning | Python 3.10+, all dependencies included | | Network monitoring | Linux: root/sudo required Β· macOS: no sudo (use pipx) Β· Windows: elevated PowerShell | | Kubernetes runtime | kubectl + read access (K8s API path) Β· Helm 3+ + root/sudo for Tetragon/eBPF (Linux only) | | Endpoint discovery | osquery (optional β€” graceful degradation if not installed) | | Layer 3 (eBPF) | Linux only β€” unavailable on macOS and Windows. K8s API path works on all platforms. | | Cloud Audit (Layer 5) | AWS credentials β€” boto3 credential chain (AWS_ACCESS_KEY_ID, ~/.aws/credentials, or instance role). If credentials are absent, the scan continues without Cloud Audit. | | SSE Proxy (Layer 5) | Zscaler ZIA: ZSCALER_API_KEY, ZSCALER_USERNAME, ZSCALER_PASSWORD, ZSCALER_TENANT Β· Prisma Access: PRISMA_CLIENT_ID, PRISMA_CLIENT_SECRET, PRISMA_TENANT_ID. Disabled by default; enable with --zscaler or --prisma-access. | | Platform upload | DefendAI API key (defendai.ai) |

Full Kubernetes setup: install.sh handles Helm, runtime monitoring setup, and permissions automatically.


DefendAI platform

AgentDiscover Scanner is the discovery layer of the DefendAI platform.

| Component | Status | Description | | ------------------------- | -------------- | --------------------------------------------------------------------- | | AgentDiscover Scanner | βœ… Open Source (v2.8.0) | Discover and classify AI agents across your environment | | defendai-agent | πŸ§ͺ Beta | MITM proxy for real-time AI traffic inspection and policy enforcement | | Correlation Engine | βœ… Available | Cross-machine identity resolution and behavioral drift detection | | Policy Engine | 🚧 Coming Soon | Define and enforce agent behavior rules | | DefendAI Platform | πŸ’Ό Enterprise | Full lifecycle governance for autonomous AI |

defendai.ai Β· playground.defendai.ai Β· [email protected]


Contributing

git clone https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner.git
cd agent-discover-scanner
uv sync
uv run pytest tests/ -v

See CONTRIBUTING.md for guidelines. Issues and PRs welcome.


License

MIT β€” free to use, deploy, and modify.


Built by DefendAI Β· Securing the future of autonomous AI

Contract & API

Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.

MissingGITHUB OPENCLEW

Contract coverage

Status

missing

Auth

None

Streaming

No

Data region

Unspecified

Protocol support

OpenClaw: self-declared

Requires: none

Forbidden: none

Guardrails

Operational confidence: low

No positive guardrails captured.
Invocation examples
curl -s "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/trust"

Reliability & Benchmarks

Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.

Missingruntime-metrics

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

Do not use if

Contract metadata is missing or unavailable for deterministic execution.
No benchmark suites or observed failure patterns are available.

Media & Demo

Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.

Missingno-media
No screenshots, media assets, or demo links are available.

Related Agents

Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.

Self-declaredprotocol-neighbors
Github OpenclewUpdated 4mo agoRank 65

@x1pay/langchain

LangChain/LangGraph tools for AI agent x402 payments on X1

OPENCLAW
Github OpenclewUpdated 4mo agoRank 65

oceanbus-langchain

LangChain tools for OceanBus β€” give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.

OPENCLAWoceanbuslangchainlangchain-tools
Machine Appendix

Contract JSON

{
  "contractStatus": "missing",
  "authModes": [],
  "requires": [],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": null,
  "outputSchemaRef": null,
  "dataRegion": null,
  "contractUpdatedAt": null,
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/snapshot",
    "contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/contract",
    "trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/trust"
  },
  "curlExamples": [
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/snapshot\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/contract\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "GITHUB_OPENCLEW",
      "generatedAt": "2026-10-08T23:15:47.154Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    },
    {
      "key": "crewai",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    },
    {
      "key": "multi-agent",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}

Facts JSON

[
  {
    "factKey": "vendor",
    "label": "Vendor",
    "value": "Defend Ai Tech Inc",
    "category": "vendor",
    "href": "https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner",
    "sourceUrl": "https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-05-31T06:17:55.034Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "protocols",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "category": "compatibility",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/contract",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-05-31T06:17:55.034Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "traction",
    "label": "Adoption signal",
    "value": "15 GitHub stars",
    "category": "adoption",
    "href": "https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner",
    "sourceUrl": "https://github.com/Defend-AI-Tech-Inc/agent-discover-scanner",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-05-31T06:17:55.034Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "handshake_status",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "category": "security",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/trust",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-defend-ai-tech-inc-agent-discover-scanner/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true,
    "metadata": {}
  }
]

Change Events JSON

[]

Sponsored

Ads related to agent-discover-scanner and adjacent AI workflows.