Evidence first
Every grade opens into the evidence behind it.
Review requested permissions, risky tool copy, credential paths, and outbound data destinations. Findings include severity, rationale, and remediation—not just a letter grade.
Security clarity for agent builders
Paste an MCP server or agent URL. AgentGrade turns permissions, unsafe tool descriptions, auth handling, and data egress into a public scorecard people can verify.
mcp-server
Scanned just now · Public scorecard
78/100
Good
Permissions
Reviewed
Prompt safety
2 findings
Data egress
Mapped
Transparent evidence. Versioned score. Shareable trust.
01 / Public method
Security trust starts with showing the work. Every scorecard points back to a public rubric and concrete evidence—no invented authority, no opaque risk model.
01
Every scoring rule is readable and versioned.
02
Every deduction points to evidence you can verify.
03
One signal users can scan before they install.
02 / The scorecard
Evidence first
Review requested permissions, risky tool copy, credential paths, and outbound data destinations. Findings include severity, rationale, and remediation—not just a letter grade.
Agent surface
See what an agent can touch before a user has to guess.
Badge loop
03 / When public isn’t enough
Block a PR when the score drops.
Re-scan when a dependency changes.
Give security review evidence, not promises.
04 / Access
Pay when AgentGrade becomes part of your private development and security workflow.
Compare plansOpen source
$0
free forever
Private assurance
$49
workspace / month
Questions, answered plainly
Your agent has a surface area