🛡️

Veragent Trust Layer

Agents:
Audits:
Secure Governance Active

Behavioral coverage

Reading a tool’s definition is cheap, so everyone reports big scan numbers. Running the server costs a sandbox each, and most of them refuse to start. This is how many we have actually executed — and exactly where our coverage stops.

140
MCP servers actually run
executed in an isolated Firecracker microVM under syscall tracing
116
SGC Certified
passed the behavioral audit with a published evidence page
938
tool invocations observed
across 131 deeply exercised servers
21
queued for audit
mostly tools someone tried to install

Where our coverage stops

We attempted 115 more servers that never started, so we have nothing to report about them. We would rather publish that than quietly count them as scanned.

Failed to start for a reason we haven't classified28
Ships no runnable entry point we could resolve23
Needs a real API key or account to start — we won't fake one7
Needs launch arguments or a subcommand we haven't inferred yet6
The package raises on its own import1
Failed before we started classifying why50

The auditor runs on its own

A one-time scan goes stale the moment a package publishes a new version. Ours wakes on a schedule, re-audits packages whose artifact changed, and records every run.

11 h ago
last audit run
102
audited in the last 7 days
13
flagged stale, re-audit queued
package changed since we audited it
9
resisted analysis
crashed our tracer instead of running

How to read these numbers. Counts only tools we actually executed in an isolated sandbox. Catalog entries carrying a heuristic score are NOT counted as audited here. Our catalog lists 766 tools, and most of them have never been run by us — a heuristic score is not an audit, and this page does not count one as if it were.

Generated Thu, 10 Sep 2026 20:55:21 GMT · recomputed every 5 minutes