GAAAS / AGENT INTELLIGENCEOne source snapshot · five evidence pillarsAUTOMATED SIGNAL. NOT CERTIFICATION.
HOW IT WORKS

From repository
to readable signal.

GAAAS makes a narrow claim on purpose: what a specific automated method observed in a specific public source snapshot—and what it could not establish.

THE PROCESS

Four steps.
No hidden leap.

  1. 01

    Name the source

    Submit one supported public GitHub repository and the agent's official domain. The repository URL fixes the source under review; the domain is separate ownership evidence.

  2. 02

    Inspect a snapshot

    GAAAS downloads a bounded source archive and applies versioned checks across security, guardrails, tooling, efficiency and Entity Trust.

  3. 03

    Publish the boundary

    The report records findings, scope, timestamp and unknowns. The first completed signal is public, while sensitive critical details are temporarily withheld.

  4. 04

    Revisit after change

    A new scan creates fresh evidence for changed code or newly verified domain control. It does not silently rewrite what an earlier scan observed.

TWO WAYS IN

Build the evidence.
Read the evidence.

FOR BUILDERS

Know what will be visible.

Prepare a public repository, review the publication boundary and use findings as leads for remediation. Verify the official domain separately when you control it.

Run a free scan
FOR BUYERS

Look past the grade.

Open the findings, confirm the method and timestamp, inspect source references and treat missing runtime evidence as unknown—not as proof of safety.

Explore the registry
EVIDENCE BOUNDARY

What the scan sees.
What it does not.

Observed

  • Supported public source files
  • Static patterns and source locations
  • Repository-authored context
  • DNS, HTTPS and policy-link evidence

Not established

  • Runtime behavior or production configuration
  • Fitness for a particular buyer or use case
  • Repository ownership from sign-in alone
  • Security, compliance or certification status
COMMON QUESTIONS

Before you rely
on a signal.

01Does a high grade prove the agent is safe?

No. It summarizes bounded automated checks of public source and domain evidence. It is not a runtime test, certification or guarantee.

02Does signing in prove repository ownership?

No. Signing in identifies the account that requested the scan. DNS verification demonstrates control of the stated domain only.

03Are private repositories supported?

No. The current scanner accepts supported public GitHub repositories and does not request private repository access.

04Why is the first report public?

The registry is designed for inspectable evidence. Publication requires explicit acknowledgement before the scan starts, and the report shows the method and its limitations.

CHOOSE THE NEXT STEP

Inspect an existing signal,
or create the next one.

Explore reportsRun a free scanRead the full standard