agenttru.st

O3 Security bronze

o3.security

Unified AI-native security platform covering code-to-runtime — agentic SAST/DAST, impact-aware SCA with function-level reachability, the BOM suite (SBOM/CBOM/AIBOM/HBOM/QBOM), supply-chain & malware defense, and eBPF runtime protection.

a2a https://mcp.o3.security/mcp talk to it https://o3.security/.well-known/agent-card.json its card
Checked 18h ago pushNotifications, stateTransitionHistory, streaming

we checked this    the operator says this

Community rating 0 0 up · 0 down — sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Google Trust Services domain-validated
Valid until 28 Nov 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified (TLSA query returned RCodeNameError)
Discovery
Well-known document
AI use policy
Search: yesAI input: yesAI training: no
What this site's robots.txt says about how AI may use its content. Recorded as the operator wrote it, not enforced — these are preferences about use, not access, and agenttru.st only reads the agent's own discovery documents.
First seen
5 Sep 2026
View verification details
Assurance
bronze Bronze — agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
? Unknown · Cloudflare, Inc. (AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
Last checked
18h ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of o3.security controls every word below.

CVE & Reachability Lookup

Look up a CVE/GHSA with CVSS, affected packages/products, EPSS exploitation probability, CISA KEV status, exploit intelligence, and reachability-aware remediation.

vulnerabilityscacvereachability
Examples it gives
  • Is CVE-2021-44228 reachable in my dependency tree?

Malicious Package Check

Check an open-source package (npm, PyPI, etc.) for known malicious activity — backdoors, infostealers, typosquats — with IOCs and remediation.

malwaresupply-chainioc
Examples it gives
  • Is the PyPI package "embiggen" malicious?

Cryptographic BOM / PQC Readiness

Discover cryptographic algorithms, keys, and protocols across code and infrastructure; forecast quantum exposure and map NIST PQC migration paths.

cbompqccryptographycompliance

BOM Generation

Generate SBOM, CBOM, AIBOM, HBOM, or QBOM with evidence mapped to regulatory frameworks (EU CRA, DORA, EO 14028, CERT-In, SEBI CSCRF).

sbomcbomaibomcompliancecyclonedxspdx

Runtime Security Events

Fetch recent eBPF runtime security events — process-tree chaining, syscall anomalies, and network egress — including zero-days detected without a published CVE.

runtimeebpfzero-daykubernetes

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
O3 Security, Inc. — what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.0.0
Auth schemes
oauth2
Card completeness
complete all eight fields required by a2a.proto v1.0
View all card details
Capabilities
pushNotifications stateTransitionHistory streaming
Agent card
https://o3.security/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.