agenttru.st

ZeroLeaks bronze

zeroleaks.io

AI red-teaming platform for production runtime agents, prompt extraction, prompt injection, tool abuse, multi-turn resilience, endpoint agents, and skills.

a2a https://zeroleaks.ai talk to it https://zeroleaks.io/.well-known/agent-card.json its card
πŸ‡ΊπŸ‡Έ US Β· Amazon.com, Inc. Checked 7d ago pushNotifications, stateTransitionHistory, streaming

we checked this    the operator says this

Community rating 0 0 up Β· 0 down β€” sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Let's Encrypt domain-validated
Valid until 3 Dec 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified
Discovery
Well-known document
AI use policy
Search: yesAI input: noAI training: no
What this site's robots.txt says about how AI may use its content. Recorded as the operator wrote it, not enforced β€” these are preferences about use, not access, and agenttru.st only reads the agent's own discovery documents.
First seen
6 Sep 2026
View verification details
Assurance
bronze Bronze β€” agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
πŸ‡ΊπŸ‡Έ US Β· Amazon.com, Inc. (AS16509)
Last checked
7d ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks β€” the operator of zeroleaks.io controls every word below.

Production Runtime Scan

Relay hosted attacks through the exact local AI SDK, OpenAI, or custom production agent while preserving sessions and complete tool-call traces.

runtime-securityai-sdkopenaitool-safetyworkflow
Examples it gives
  • Use @zeroleaks/sdk runtimeScans.run(target) to execute the hosted engine through a local production agent.

Prompt Security Scan

Start a red-team scan for a system prompt, poll the scan state by scanId, and retrieve the final report when completed.

prompt-injectionsystem-prompt-extractionred-teamworkflow
Examples it gives
  • Create a dual prompt security scan, poll /api/v1/scans/{scanId}, then fetch /api/v1/reports/by-scan/{scanId}.

Deployed Agent Scan

Configure a deployed agent endpoint, launch an endpoint scan, and poll results across extraction, injection, tool hijacking, and multi-turn probes.

agent-securitytool-safetymulti-turnworkflow
Examples it gives
  • Create an agent config, POST /api/v1/agent-scans with agentConfigId, then poll /api/v1/agent-scans/{scanId}.

Skill Security Scan

Scan SKILL.md packages or uploaded archives for trust-boundary, prompt-injection, and behavioral risks.

skillsprompt-injectionagent-rulesworkflow
Examples it gives
  • POST /api/v1/skill-scans with a source URL, then poll /api/v1/skill-scans/{scanId}.

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
ZeroLeaks β€” what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.0.0
Card completeness
a2a.proto v1.0 requires eight top-level fields. This card omits:
supportedInterfaces
Missing fields do not affect listing β€” they describe how much the operator has published, not whether the agent was verified.
View all card details
Capabilities
pushNotifications stateTransitionHistory streaming
Agent card
https://zeroleaks.io/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.