Code, Build and Evaluate agents - excellent Model and Skills/MCP/ACP/A2A Support
- vulnerabilities attested + 7
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 5
- trust mitigators mixed − 8
attested inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 36s ago · see ecosystem CVEs →
- C · 52 → C · 59
- C · 44 → C · 52
- A · 0 → C · 44
- medium dangerous code
dynamic exec: eval()/exec()
analyzed commit 167e9e2 · analyzer v28 · 1d ago
skills & prompt files 4
- agent-rules evalstate-fast-agent-167e9e2/AGENTS.md
- skill evalstate-fast-agent-167e9e2/examples/hf-toad-cards/skills/pr-writing-review/SKILL.md
- skill evalstate-fast-agent-167e9e2/examples/hf-toad-cards/skills/session-investigator/SKILL.md
- agent-rules evalstate-fast-agent-167e9e2/tests/integration/function_tools/agent.md
danger signals2
- dynamic code execution eval()/exec() evalstate-fast-agent-167e9e2/scripts/gen_schema.py :161
exec(content, namespace) - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform evalstate-fast-agent-167e9e2/src/fast_agent/llm/provider/anthropic/vertex_config.py :26
_CLOUD_PLATFORM_SCOPE = "https://www.googleapis.com/auth/cloud-platform"
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of evalstate.