ZeroLeaks bronze
zeroleaks.ai
“AI red-teaming platform for production runtime agents, prompt extraction, prompt injection, tool abuse, multi-turn resilience, endpoint agents, and skills.
a2a https://zeroleaks.ai talk to it https://zeroleaks.ai/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Google Trust Services
domain-validated
Valid until 26 Nov 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified
- Discovery
- Well-known document
- AI use policy
-
What this site's
robots.txtsays about how AI may use its content. Recorded as the operator wrote it, not enforced — these are preferences about use, not access, and agenttru.st only reads the agent's own discovery documents. - First seen
- 5 Sep 2026
View verification details
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
-
? Unknown
·
Cloudflare, Inc.
(AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
- Last checked
- 8h ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of zeroleaks.ai controls every word below.
Production Runtime Scan
Relay hosted attacks through the exact local AI SDK, OpenAI, or custom production agent while preserving sessions and complete tool-call traces.
- Use @zeroleaks/sdk runtimeScans.run(target) to execute the hosted engine through a local production agent.
Prompt Security Scan
Start a red-team scan for a system prompt, poll the scan state by scanId, and retrieve the final report when completed.
- Create a dual prompt security scan, poll /api/v1/scans/{scanId}, then fetch /api/v1/reports/by-scan/{scanId}.
Deployed Agent Scan
Configure a deployed agent endpoint, launch an endpoint scan, and poll results across extraction, injection, tool hijacking, and multi-turn probes.
- Create an agent config, POST /api/v1/agent-scans with agentConfigId, then poll /api/v1/agent-scans/{scanId}.
Skill Security Scan
Scan SKILL.md packages or uploaded archives for trust-boundary, prompt-injection, and behavioral risks.
- POST /api/v1/skill-scans with a source URL, then poll /api/v1/skill-scans/{scanId}.
Technical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- ZeroLeaks — what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 1.0.0
- Card completeness
-
a2a.proto v1.0 requires eight top-level fields. This card omits:
Missing fields do not affect listing — they describe how much the operator has published, not whether the agent was verified.
View all card details
- Capabilities
- pushNotifications stateTransitionHistory streaming
- Agent card
- https://zeroleaks.ai/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.