Trust scoring for AI agents. Investigate, verify, and compare agent trustworthiness through MCP.
AgentScore MCP demonstrates solid definition quality with well-structured tools, comprehensive parameter documentation, and explicit input schemas. All three tools have clear descriptions (143-296 chars, within the 10-1024 char baseline). Parameters are properly typed with enums where appropriate (platform, depth, format). However, output schemas are not explicitly documented in the visible source code, and error handling guidance is implicit rather than explicit. Tool naming follows verb-noun convention appropriately (agentscore, sweep, xray are domain-specific verbs). The server uses current MCP SDK patterns and includes tool annotations (risk markers). Strengths: explicit enums for constrained inputs, parameter descriptions include context and examples. Gaps: no visible output schema documentation, error recovery paths not stated in descriptions, no examples of dependent parameter relationships.
Investigate a single agent's trustworthiness. Returns a detailed trust score (0-1000), recommendation tier (EXCELLENT/TRUSTWORTHY/CAUTION/CRITICAL), reasoning, and evidence from the agent's profile, content, and interactions.
Compare multiple agents in a thread for coordinated trust attacks (sock puppets, vote manipulation). Returns comparative scores, interaction patterns, and flags for suspicious behavior or coordinated inauthentic activity.
X-ray content for hidden AI-targeted payloads. Detects concealed instructions in markdown, HTML, code, and text before an agent consumes it, including hidden comments, invisible unicode, CSS-hidden text, encoded payloads, code comments, and structural hiding tricks.
Output schemas not explicitly documented. Tool descriptions state WHAT is returned ('detailed trust score', 'comparative scores', 'detected payloads') but do not provide structured field specifications or data types. LLMs cannot reliably extract and chain outputs without documented return types.
Error handling guidance missing from tool descriptions. No mention of what errors are possible, when to retry, or what the LLM should do if a call fails (e.g., 'Unknown handle: try verifying the platform is correct'). Descriptions do not include recovery paths.
agentscore and sweep tools describe enum values (demo, json, moltbook, github) but do not explain when to use each platform or what data each adapter provides. This requires the LLM to guess the correct platform context.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 47 | - | v1 |
depth parameter ('quick'/'standard'/'deep') is described with item counts (50/100/500) but not with guidance on when to select each. LLMs cannot infer whether 'deep' is needed without explicit heuristics (e.g., 'Use deep only if initial analysis flags suspicious patterns').