O3 Security bronze
o3.security
“Unified AI-native security platform covering code-to-runtime — agentic SAST/DAST, impact-aware SCA with function-level reachability, the BOM suite (SBOM/CBOM/AIBOM/HBOM/QBOM), supply-chain & malware defense, and eBPF runtime protection.
a2a https://mcp.o3.security/mcp talk to it https://o3.security/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Google Trust Services
domain-validated
Valid until 28 Nov 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified (TLSA query returned RCodeNameError)
- Discovery
- Well-known document
- AI use policy
-
What this site's
robots.txtsays about how AI may use its content. Recorded as the operator wrote it, not enforced — these are preferences about use, not access, and agenttru.st only reads the agent's own discovery documents. - First seen
- 5 Sep 2026
View verification details
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
-
? Unknown
·
Cloudflare, Inc.
(AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
- Last checked
- 18h ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of o3.security controls every word below.
CVE & Reachability Lookup
Look up a CVE/GHSA with CVSS, affected packages/products, EPSS exploitation probability, CISA KEV status, exploit intelligence, and reachability-aware remediation.
- Is CVE-2021-44228 reachable in my dependency tree?
Malicious Package Check
Check an open-source package (npm, PyPI, etc.) for known malicious activity — backdoors, infostealers, typosquats — with IOCs and remediation.
- Is the PyPI package "embiggen" malicious?
Cryptographic BOM / PQC Readiness
Discover cryptographic algorithms, keys, and protocols across code and infrastructure; forecast quantum exposure and map NIST PQC migration paths.
BOM Generation
Generate SBOM, CBOM, AIBOM, HBOM, or QBOM with evidence mapped to regulatory frameworks (EU CRA, DORA, EO 14028, CERT-In, SEBI CSCRF).
Runtime Security Events
Fetch recent eBPF runtime security events — process-tree chaining, syscall anomalies, and network egress — including zero-days detected without a published CVE.
Technical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- O3 Security, Inc. — what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 1.0.0
- Auth schemes
- oauth2
- Card completeness
- complete all eight fields required by a2a.proto v1.0
View all card details
- Capabilities
- pushNotifications stateTransitionHistory streaming
- Agent card
- https://o3.security/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.