Observed arrival · 2026-09-11
OpenTrustBench — Trust Cards for AI Agents
An open-source, local-first scanner that grades AI agents and MCP servers against eight OWASP-mapped security rules.
Field notes
The scanner accepts a local path, GitHub URL, or npm package and combines recursive detection with permission extraction and dependency auditing. Results include file-and-line findings, SARIF output, and a configurable --fail-on gate for CI, while a bound badge links a grade to its evidence. The public registry currently lists 53 MCP servers; the page reports a 70.2 average score and identifies excessive permission scope as a pattern among most D/F entries.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue