Know what will be visible.
Prepare a public repository, review the publication boundary and use findings as leads for remediation. Verify the official domain separately when you control it.
Run a free scanGAAAS makes a narrow claim on purpose: what a specific automated method observed in a specific public source snapshot—and what it could not establish.
Submit one supported public GitHub repository and the agent's official domain. The repository URL fixes the source under review; the domain is separate ownership evidence.
GAAAS downloads a bounded source archive and applies versioned checks across security, guardrails, tooling, efficiency and Entity Trust.
The report records findings, scope, timestamp and unknowns. The first completed signal is public, while sensitive critical details are temporarily withheld.
A new scan creates fresh evidence for changed code or newly verified domain control. It does not silently rewrite what an earlier scan observed.
Prepare a public repository, review the publication boundary and use findings as leads for remediation. Verify the official domain separately when you control it.
Run a free scanOpen the findings, confirm the method and timestamp, inspect source references and treat missing runtime evidence as unknown—not as proof of safety.
Explore the registryNo. It summarizes bounded automated checks of public source and domain evidence. It is not a runtime test, certification or guarantee.
No. Signing in identifies the account that requested the scan. DNS verification demonstrates control of the stated domain only.
No. The current scanner accepts supported public GitHub repositories and does not request private repository access.
The registry is designed for inspectable evidence. Publication requires explicit acknowledgement before the scan starts, and the report shows the method and its limitations.