Who it is for
FrontierAgent is an open-source agent runtime, terminal product, and evaluation
README.md:30suite for long-horizon research and file-based work. The frontier-agent TUI
README.md:31ships two native workflows:
README.md:32
Scanned repository says: FrontierAgent is an open-source agent runtime, terminal product, and evaluation
Inspect GitHub sourceVotes show community interest, not safety. They never change this score.
Critical finding · details withheld for 30 days
Inspect the findingsRuntime safety, real-world agent capability, fitness for your use case or independent certification.
Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.
FrontierAgent is an open-source agent runtime, terminal product, and evaluation
README.md:30suite for long-horizon research and file-based work. The frontier-agent TUI
README.md:31ships two native workflows:
README.md:32No explicit capability or integration was extracted; that does not mean none exists.
Manifest declares Python >=3.12 as a requirement.
pyproject.toml:7Declares a dependency on apodex-agent-core.
pyproject.toml:11Declares a dependency on pydantic.
pyproject.toml:12Declares a dependency on pydantic-settings.
pyproject.toml:13Declares a dependency on openai.
pyproject.toml:14Declares a dependency on anthropic.
pyproject.toml:15Declares a dependency on httpx.
pyproject.toml:16A license or copying file is present; its terms have not been reviewed.
LICENSE:1These are references in selected source files, not proof that a feature works at runtime.
Observed in the scanned archive at Oct 9, 2026, 2:20 PM UTC. Archive digest sha256:12fb276a7ac11ab2…. Source links open current GitHub HEAD and may differ from the scan. Repository statements are unreviewed and do not affect the score.
Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.
Details are withheld from public view for 30 days after the scan. The owner can see them in full.
Review the private assessment and address the finding.
Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.
Verify the domain using the Metal Mantra DNS TXT challenge.
No privacy policy link was found on the stated homepage. Buyers cannot see how the vendor handles their data.
Expose a clear Privacy Policy link on the official homepage.
No terms link was found on the stated homepage. Buyers cannot see the conditions that apply to using the service.
Expose a clear Terms link on the official homepage.
Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.
No user reports yet.
Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.
Share the full report so its scope and limits travel with the score.