This page explains the registry, not the agent directory. gitleaks, Semgrep, and Trivy examine pinned source. A failed or incomplete scan never becomes a pass. A CLEAN result is not permission to deploy.
Scans lockfiles and transitive dependencies against our CVE database. Identifies known-malicious packages, deprecated registries, and supply-chain anomalies before they reach production.
Tier-2 verdicts combine the scanner evidence available for each source. Entries without sufficient evidence remain visibly pending or incomplete.
Tier-2 audit pipeline active across the public registry.
Working with an authorized repository and need help interpreting the available evidence? Send the source and the decision you need help making. Do not send credentials by email.
Request a scoped review →