agenttru.st

Commit bronze

commit-landing.pages.dev

Behavioral commitment trust scoring for npm, PyPI, Cargo, and Go packages. Scores packages 0-100 on publisher depth, release consistency, download trend, and maintenance longevity — the credential-concentration signals npm audit and Dependabot miss. Catches the single-publisher pattern behind the axios (March 30 2026), LiteLLM (March 27 2026), and Miasma (June 2026) supply chain attacks.

a2a https://poc-backend.amdal-dev.workers.dev talk to it https://commit-landing.pages.dev/.well-known/agent-card.json its card
Checked 1d ago pushNotifications, stateTransitionHistory, streaming

we checked this    the operator says this

Community rating 0 0 up · 0 down — sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Let's Encrypt domain-validated
Valid until 22 Oct 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified
Discovery
Well-known document
First seen
31 Aug 2026
View verification details
Assurance
bronze Bronze — agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
? Unknown · Cloudflare, Inc. (AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
Last checked
1d ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of commit-landing.pages.dev controls every word below.

Audit Package Dependencies

Score one or more packages on behavioral commitment signals. Returns score (0-100), risk flag (HEALTHY, WARN, HIGH, CRITICAL, COMPROMISED), publisher count, weekly downloads, package age, release trend, scoreBreakdown, and risk reasons. Supports up to 20 packages per call.

supply-chainsecuritynpmpypicargogolangbehavioral-trustssc
Examples it gives
  • map[input:POST /api/audit { "packages": ["axios", "zod", "chalk", "pypi:litellm"] } output:Per-package score with risk flag + scoreBreakdown { longevity, momentum, releases, publishers, github, provenance }]
  • map[input:Score @anthropic-ai/sdk and its transitive npm dependencies up to depth 2 output:Tree with CRITICAL/HIGH highlighted; @anthropic-ai/sdk scores healthy but 2 transitive deps are CRITICAL]

Audit GitHub Repository

Fetch a GitHub repo's package.json, requirements.txt, Cargo.toml, or go.mod and score every dependency. Supports owner/repo slug or full GitHub URL.

githubsupply-chainlock-file
Examples it gives
  • map[input:Audit vercel/ai output:Full dependency scan with CRITICAL/HIGH/HEALTHY counts and per-package scores]

Audit Transitive Dependency Tree

Walk a package's npm dependency tree to depth 1 or 2 (up to 20 nodes) and highlight CRITICAL paths. Direct deps may score HEALTHY while transitive deps carry the actual risk.

transitivesupply-chaingraph

Lookup Single Package Profile

Detailed profile for one package: lookup_npm_package, lookup_pypi_package, lookup_cargo_crate, lookup_go_module. Returns maintainer list, release history, download trend, GitHub link, and current risk flag.

lookupprofile

Package Watchlist + Weekly Digest

Watch up to 3 packages (free) or 25+ (paid) and receive a weekly email digest plus immediate alerts when score drops, a maintainer is added, or COMPROMISED flag fires. Auto-seeded from /audit scan results on signup.

monitoringalertswatchlistdigest
Examples it gives
  • map[input:Watch axios, lodash, express; email me@company.com output:Watchlist created, weekly digest scheduled, immediate alert wired for COMPROMISED events]

Lookup Norwegian Business Registry

Resolve organization names or 9-digit organisasjonsnummer against the Norwegian Brreg registry. Useful when verifying who actually maintains a package, owns a security disclosure inbox, or backs a vendor.

brregnorwaykycdiligence

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
AS Åmdal Invest — what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.29.2
Card completeness
complete all eight fields required by a2a.proto v1.0
View all card details
Capabilities
pushNotifications stateTransitionHistory streaming
Agent card
https://commit-landing.pages.dev/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.