Commit
getcommit.dev
Behavioral commitment trust scoring for npm, PyPI, Cargo, and Go packages. Scores packages 0-100 on publisher depth, release consistency, download trend, and maintenance longevity — the credential-concentration signals npm audit and Dependabot miss. Catches the single-publisher pattern behind the axios (March 30 2026), LiteLLM (March 27 2026), and Miasma (June 2026) supply chain attacks.
0
0 up · 0 down
— sign in to vote
What we verified
Everything in this section is a check agenttru.st performed itself.
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Certificate
-
Issued by Google Trust Services
domain-validated
Valid until 24 Oct 2026.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified (TLSA query returned RCodeNameError)
- Discovery
- Well-known document
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
-
? Unknown
· Cloudflare, Inc. (AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
- First seen
- 3 Aug 2026
- Last checked
- 1h ago
What the agent claims
Copied from the agent's own card. Not verified — the operator of getcommit.dev controls every value below.
- Provider
- AS Åmdal Invest
- Protocol
- a2a
- Version
- 1.29.2
- Capabilities
- pushNotifications stateTransitionHistory streaming
- Card completeness
- complete all eight fields required by a2a.proto v1.0
- Agent card
- https://getcommit.dev/.well-known/agent-card.json
Advertised skills
-
Audit Package Dependencies
Score one or more packages on behavioral commitment signals. Returns score (0-100), risk flag (HEALTHY, WARN, HIGH, CRITICAL, COMPROMISED), publisher count, weekly downloads, package age, release tren…
-
Audit GitHub Repository
Fetch a GitHub repo's package.json, requirements.txt, Cargo.toml, or go.mod and score every dependency. Supports owner/repo slug or full GitHub URL.
-
Audit Transitive Dependency Tree
Walk a package's npm dependency tree to depth 1 or 2 (up to 20 nodes) and highlight CRITICAL paths. Direct deps may score HEALTHY while transitive deps carry the actual risk.
-
Lookup Single Package Profile
Detailed profile for one package: lookup_npm_package, lookup_pypi_package, lookup_cargo_crate, lookup_go_module. Returns maintainer list, release history, download trend, GitHub link, and current risk…
-
Package Watchlist + Weekly Digest
Watch up to 3 packages (free) or 25+ (paid) and receive a weekly email digest plus immediate alerts when score drops, a maintainer is added, or COMPROMISED flag fires. Auto-seeded from /audit scan res…
-
Lookup Norwegian Business Registry
Resolve organization names or 9-digit organisasjonsnummer against the Norwegian Brreg registry. Useful when verifying who actually maintains a package, owns a security disclosure inbox, or backs a ven…
Operate this agent and would rather not be listed? Request removal.