Use Metal Mantra,
step by step.
Everything you can do here, in plain language: read a report, find an agent, publish your own signal, verify your domain and manage re-scans. Pick the path that matches you.
Start here
Metal Mantra is a public registry of AI agents. For each agent it shows what an automated scan found in the source, what the owner can prove about their domain, and what could not be checked.
There are two kinds of visitors, and you can be both.
- Buyers
- You want an agent for a job and need evidence beyond a README and a star count. You do not need an account to browse, search and compare. You need one only to vote.
- Builders
- You made an agent and want a public, readable report for it. You sign in, add your repository and your domain, and get a report you can share.
| Your situation | Use | Evidence it produces |
|---|---|---|
| Source is public on GitHub | Public scan | Strongest. We read the source ourselves. |
| Source is private on GitHub | CI attestation | Weaker. You run our scanner; we cannot reproduce it. |
| No source, just a hosted agent | Endpoint-only | Weakest. Reads the agent card, grade stops at BBB. |
| Looking for an agent to use | Registry and matching | Reports from all three, clearly labeled. |
Read a report in two minutes
Every public report is built the same way, so you can read any of them with the same four stops.
- Start here box
The first thing on a report. It names the most serious finding, or says that no rule matched and that this still is not proof of safety. Beside it, a short note lists what the report does not establish.
- Findings
Each finding has a severity, the rule that matched, an explanation, a suggested action and, for public source, a link to the file and line. Filter by severity or pillar. Open a few before you decide anything.
- Evidence and limits
How many files were read, whether that was the whole eligible selection, and when. Domain checks (DNS, HTTPS, privacy and terms links) are shown here too. This is where the report says what it could not see.
- Score breakdown
Each pillar's score and weight, so you can see exactly how the overall number was made.
The grade
Few or no rule matches in what was scanned.
Some matches. Read the findings.
Many or serious matches. Read before you buy.
A grade only compares reports made with the same method. Do not compare a v0.2 score with an archived v1 score.
The five pillars
- Security and privacy: hardcoded secrets, running generated code, untrusted text in privileged prompts, user-controlled network destinations.
- Guardrails and loop control: token ceilings, rate limits, loops that can run forever, sensitive actions without human approval.
- Schema and tooling: model output validated at runtime, no raw text returned, citations for retrieval answers.
- Token and cost efficiency: model fallbacks, caching, bounded history and input size.
- Entity trust: domain control, HTTPS, and links to a privacy policy and terms.
How the number is made
Each pillar starts at 100. Every finding takes points off that pillar, more for serious ones. The overall score is the weighted sum of the five pillars.
| Severity | Meaning | Typical deduction |
|---|---|---|
| CRITICAL | Could let an attacker or a runaway process do real damage. | 18 – 22 points |
| MAJOR | A clear gap in a safeguard. | 10 – 16 points. Domain checks in Entity trust cost more: 25 – 50 |
| MINOR | Worth tidying up, lower risk. | 8 – 15 points |
Example: a guardrails pillar with an unbounded model loop (−22) and a request without a token ceiling (−12) scores 66 out of 100, and contributes 66 × 25% = 16.5 points to the overall score.
Labels you may see
| Label | What it tells you |
|---|---|
| Public report | Made by Metal Mantra from public source and domain checks. |
| CI-attested | Private source. The owner ran our scanner in their CI. GitHub confirms which repository and commit ran, but we never saw the code. |
| …with pinned scanner | As above, but run through Metal Mantra's own reusable workflow, so the owner could not alter the scanner or the files it read. |
| Endpoint only | No source was inspected. Built from the agent card the owner publishes. |
| Archived v1 | An older method with four pillars. Not comparable with v0.2. |
| Domain verified at scan | The owner proved DNS control of the domain at the time of the scan. It is a statement about the scan, not about today. |
| Partial selection | The repository was larger than the scan limits, so only part of it was read. |
Find and compare agents
Two ways in: describe the job and get suggestions, or browse the registry with filters.
Describe the job (home page)
- Open the home page and choose “Buy an agent”.
Write what you need in your own words, up to 500 characters. Any language works.
- Optional: tick “Rank with AI”.
Your description is sent once to our AI provider (Anthropic) to choose up to three agents, and is not stored. Without the box, matching runs in your browser tab only and nothing is sent.
- Read the results as leads.
Each suggestion quotes a statement from the agent's own repository. That is what the repository claims, not verified job fit. Open “Inspect evidence” to read the full report. A framework may need development before you can use it.
If the AI option is unavailable, the page falls back to keyword matching and says so.
Browse the registry
Open Agent registry. Search by agent or builder name, then narrow with the filters.
| Control | What it does |
|---|---|
| Method | Agent Signal v0.2 or Archive v1. Choose one before you filter by grade. |
| Grade | AAA, BBB or CCC for v0.2. Only available once you pick a method. |
| Scope | Complete selection means every eligible file was read. Partial means the repository was larger than the limits. |
| Topic (inferred) | A category guessed from the repository's own text. It helps you browse and is not verified. |
| Domain | Show only agents whose owner proved domain control at scan time. |
| Sort | Latest scan, Name, Score within method, Top this week (votes), or Recently pushed (last GitHub push). |
Open “How results are ordered” on the page for the exact rules. No payment affects order.
Compare side by side
Tick up to three reports, then press “Compare reports”. You can only compare reports from the same method, because scores from different methods mean different things.
Votes
A vote shows community interest. It never changes a score or grade. To vote you must be signed in with an account at least 24 hours old, you can vote once per agent, up to 30 new votes a day, and you cannot vote for an agent you scanned. “Top this week” counts votes since Monday 00:00 UTC.
User reports
Under a report you can say whether the agent worked or failed for you, with a short note. Each report is one signed-in GitHub account's statement. We do not verify that the account ran the agent, and reports never change a score, grade or order. You need an account at least 24 hours old, you can add one report per agent (and change or remove it), and notes are plain text with no links. You cannot report on an agent you scanned, but you can reply to reports on it. For a security problem, use the disclosure page instead of a public note.
Ask Claude or ChatGPT
The registry can be added as a read-only connector, so an assistant can search it, read a report and check an agent before you rely on it. No sign-in is needed. The address is https://metalmantra.io/mcp.
- Add it as a custom connector.
In Claude, open Settings, then Connectors, then add a custom connector with that address. In ChatGPT, add it as a connector in developer mode with the same address and no authentication.
- Ask in plain words.
For example: “Find an agent that triages support tickets, then check whether it meets a score of 80.” The assistant calls
search_agents,get_agent_reportandverify_trust. - Read the verdict as a lead.
unknownmeans the agent has not been checked, never that it is safe. Text quoted from a repository is passed along as data, not as instructions. Results are automated signals, not a certification.
Visit vendor site
The link appears only when the agent was scanned and its owner verified the domain by DNS. We re-check weekly and hide the link if the record is gone. Links are not for sale. For a CCC grade or a critical finding, a caution appears beside the link: read the report before you buy.
Scan a public repository
Your first scan is free. The report is public the moment it finishes.
Before you start
- The repository is public on GitHub and contains an AI agent (a model call with tool use, an agent framework or an agent loop). Generic SaaS code is not accepted.
- The code is JavaScript, TypeScript or Python.
- You know the official domain of the agent, for example
example.com. - You can sign in with GitHub or ChatGPT.
- Open Scan and sign in.
GitHub sign-in asks only to read your public profile and email. It does not request access to your repositories.
- Paste the repository URL and the domain.
Use the form
https://github.com/owner/repo. An unverified domain is allowed, but it is clearly marked and costs points in Entity trust. - Tick the consent box.
It confirms you understand that the first report is public immediately and may contain redacted findings.
- Press “Run scan and publish report”.
We download a snapshot, apply the rules, check the domain, and take you to the public report. Do not close the tab while it runs.
- Read your report, then fix and verify.
Use the suggested actions to improve the code, and verify your domain to unlock one free re-scan.
What gets read
| Limit | Value |
|---|---|
| File types | .js .jsx .mjs .cjs .ts .tsx .py |
| Files per scan | Up to 80, each up to 120 KB, 4 MB in total |
| Download size | Repository archive up to 12 MB |
| Skipped | node_modules, vendor, dist, build, tests, minified and type-definition files |
| Order | Product source first (src, lib, app, server), then other files, then examples, docs and tooling |
If a repository is bigger than the limits, the report says it is a partial selection and shows how many files were read.
After the scan
- Critical findings are hidden from public view for 30 days. You see them in full in your private report under Your account.
- Metal Mantra does not promise to notify maintainers before details are revealed. If a finding is wrong or sensitive, use the support form early. See the disclosure note.
- Scanning does not prove ownership. Disputes about who controls a repository go to support.
Verify your domain
Verification proves you control the domain you named. It raises the Entity trust pillar and unlocks a free re-scan.
- Open your private report.
Go to Your account, find the agent and choose “Open private report”. Scroll to “Your evidence workspace” and “Verify domain control”.
- Copy the DNS record shown there.
You will see a Name and a Value. They look like this, with your own domain and token:
Type TXT Name _metalmantra.example.com Value metalmantra-verification=<your-token> - Add it at your DNS provider.
Some providers want only
_metalmantraas the host, because they add your domain for you. Paste the value exactly, without extra quotes or spaces. - Wait, then press “Check DNS record”.
DNS can take a few minutes or longer to spread. If it says the record was not found yet, wait and try again.
- Run a new scan.
Verification does not change an existing score. Your first successful verification gives you one free re-scan so the new evidence can be included. Use “Start a new scan” in the same workspace.
Records created under our earlier name (_gaaas) still work.
Re-scans, credits and payment
Re-scan after real changes to code or controls. A new scan creates fresh evidence; it never rewrites an old report.
| Item | Price | What it gives |
|---|---|---|
| First scan | Free | One public report for a supported repository. |
| First DNS verification | Free | One free re-scan, once per repository. |
| Re-audit pass | $29, one time | Three re-scans for one repository. No subscription or auto-renewal. |
| Organization | Custom | For teams with several agents. Talk to us through support. |
Buy a re-audit pass
- Finish your free scan first.
Passes are for repositories you have already scanned.
- Start another scan on Scan.
When no credits are left you will see “A re-audit pass is required”, with a “Buy a re-audit pass” button.
- Pay on the secure checkout page.
Payments are handled by Dodo Payments, which acts as Merchant of Record: it charges you, collects tax and sends your receipt. Metal Mantra never sees your card details.
- Come back and scan.
Credits arrive as soon as the payment is confirmed, usually within seconds. They appear under “Credits and purchases” on Your account.
Refunds
- If you have not used any of the three re-scans, you can ask for a full refund within 14 days of purchase through the support form.
- After a re-scan from the pass is used, it is not refundable, except where the law requires it or a re-scan failed because of a fault on our side.
- An approved refund removes the unused credits. A refund does not change a published report.
Private repository: publish from your own CI
For commercial agents whose source is not public. You run our scanner inside your GitHub Actions and we publish the result. Your code never leaves your runner.
- Register your repository on Scan / Private.
Sign in, then enter the private repository URL and your official domain. The repository must be private or internal. If it is public, use the normal scan instead.
- Copy the workflow we give you.
It is a short GitHub Actions file with your registration id inside. The registration id is not a secret.
- Commit it to your repository.
Save it as
.github/workflows/scan.yml. It runs on pushes tomain, weekly on Mondays at 06:00 UTC, and whenever you start it by hand. - Run it once from the Actions tab.
Choose “Metal Mantra agent signal” and press “Run workflow”. The log shows exact file locations for your own use.
- Your report goes public after the first successful run.
Find it in the registry, labeled CI-attested.
What leaves your runner
- Only rule ids and how many times each matched, plus file counts and the commit. No paths, no lines, no excerpts, no code.
- GitHub signs a short-lived identity token that proves which repository and commit made the request. We check it, rebuild every finding from our own rule list, and compute the domain evidence ourselves.
Rules to know
- Only pushes, scheduled runs, manual runs and releases publish. Pull request runs never do.
- One report per registration every 10 minutes. No credits are needed, because you pay for the compute in your own CI.
- You cannot take over a profile owned by another account, and a deleted or transferred repository cannot reuse an old registration.
Hosted agent with no code to share
If your agent is a hosted service, we can read the public agent card on your domain and publish a limited signal.
What you need
- A domain you control.
- An A2A-style agent card at
https://your-domain/.well-known/agent-card.json(oragent.jsonin the same folder). It must have a name and list skills or capabilities. A generic website is rejected.
- Open Scan / Endpoint and sign in.
Enter your domain and press “Check and publish”.
- Add the DNS TXT record it shows.
The first press returns a record to add, in the same format as domain verification. This proves you control the domain.
- Press “Check again”.
We fetch your card, score it and publish the report. We re-check DNS on every publish, so a record you remove later stops working.
What is scored
| Scored | Not assessed |
|---|---|
| Security and privacy: declared authentication, HTTPS, interfaces on the same domain | Guardrails and loop control |
| Schema and output: skills, descriptions, input and output modes | Token and cost efficiency |
| Entity trust: provider, version, documentation, plus our own DNS, HTTPS and policy-link checks |
Weights are rescaled over the three scored pillars, and the grade cannot go above BBB, because a card is a claim and not behavior. The report says so on its face.
- One check per agent every 10 minutes.
- We only fetch the fixed well-known paths on your verified domain, over HTTPS, with a 256 KB cap and a six-second timeout.
- If you later have a repository we can read, a normal scan gives a stronger signal.
Account and sign-in
Sign in with GitHub or ChatGPT. GitHub sign-in asks only for your public profile and verified email and never for repository access. Matching verified emails are joined into one account. A sign-in lasts 30 days, and you can sign out any time.
Your private Account page shows:
- Your agents
- Every repository you scanned, with grade, score, visibility and domain status. “Open private report” gives you the owner workspace with full details and DNS verification. “View public page” opens the public report.
- Credits and purchases
- Re-scans left per repository and your recent purchases with their status.
- Support requests
- What you sent and whether it is open or resolved.
- Sign-in
- Your email, linked providers and a sign-out button.
Only you can see this page.
When something goes wrong
| Message | What it means | What to do |
|---|---|---|
| Only public GitHub repositories are supported. / Repository not found or not public. | The URL is wrong, or the repository is private. | Check the URL. For a private repository, use the CI route. |
| No autonomous agent runtime or tool-calling evidence was found… | The code does not look like an AI agent. This registry accepts agents, not general SaaS. | Scan the repository that holds the agent's loop or tool calls. |
| No supported source files were found in this repository. | There is no JavaScript, TypeScript or Python source in the files we can read. | Scan the repository that contains the agent code. |
| Repository archive is too large for the free scan. | The download is over 12 MB. | Scan a smaller repository or contact support. |
| Daily scan limit reached. Try again tomorrow. | You used today's 5 scans, including failed ones. | Wait until tomorrow. |
| A re-audit pass is required for another scan. | You have no credits left on this repository. | Verify your domain for one free re-scan, or buy a pass. |
| This repository's re-audit pass belongs to another account. | A different account scanned this repository first. | Contact support to sort out ownership. |
| GitHub took too long to respond. Try again. | GitHub was slow. | Try again in a minute. |
| TXT record not found yet. | The DNS record has not spread, or the value does not match. | Check name and value, wait, then check again. |
| This agent was checked a few minutes ago. | Endpoint and CI reports are limited to one every 10 minutes. | Wait ten minutes. |
| This agent profile belongs to another account. | Someone else already published this agent. | Contact support with proof of control. |
Other things
- No “Continue with GitHub” button. Use “Continue with ChatGPT”. Both reach the same features.
- Vote button does nothing. Your account may be under 24 hours old, or you scanned that agent yourself, or you reached 30 votes today.
- A report looks wrong. Use “Report a problem with this report” at the bottom of the report. It fills in the report for you.
- Your form was lost after sign-in. The scan form remembers the repository and domain in your browser tab. Open the form again in the same tab.
Get help
Use the support form. Pick the topic that fits and include the report URL.
| Topic | Use it for |
|---|---|
| A scan or report | A wrong finding, missing evidence, a scan that failed. |
| Repository claim or ownership | You maintain a repository someone else scanned, or a pass is tied to the wrong account. |
| Privacy or data request | Access, correction or removal of your information. |
| Security disclosure | A vulnerability in Metal Mantra itself, or a sensitive finding. |
| Account access | Sign-in problems, refunds and purchases. |
Prefer email? hello@metalmantra.io for general questions, security@metalmantra.io for security, privacy@metalmantra.io for privacy. Never send passwords, private keys or exploit details.
Common questions
Does a high grade mean an agent is safe?+
No. A grade summarizes what automated static checks found in a bounded snapshot of source. It says nothing about how the agent behaves in production, how it is configured, or whether it fits your job. Treat it as a reason to look closer, never as a certificate.
Does an empty findings list mean nothing is wrong?+
No. It means none of the rules matched inside the files that were scanned. Unscanned files, dependencies, runtime configuration and real behavior are all unknown.
Can I scan a repository I do not own?+
The scan itself does not check ownership, so anyone signed in can scan a supported public repository. That is why the report says so plainly: starting a scan does not prove you maintain the code. If a maintainer disagrees with a report, they can ask for a correction through the support form.
Why were critical details hidden on a report?+
For the first 30 days after a scan, public views replace the title, description, fix and source location of critical findings with a notice. The score and the other findings stay visible. The owner sees everything in their private report. After 30 days the details may be revealed automatically.
Why can't I sort by stars?+
Stars are easy to buy and measure fame, not quality. The registry shows them for context only and never uses them to order or score agents.
Can I pay to improve my score or my ranking?+
No. Payment buys extra re-scans only. It never changes a score, a grade, the order of the registry or whether a vendor link is shown.
Glossary
- Agent Signal v0.2
- The current method: five weighted pillars scored from source and domain evidence. It is the only method new scans use.
- Archive v1
- An earlier four-pillar method. Old reports stay readable, but their scores cannot be compared with v0.2.
- Pillar
- One of the five areas scored in a report: security and privacy, guardrails, schema and tooling, cost efficiency, and entity trust.
- Finding
- One place where a rule matched. Each has a severity, an explanation, a suggested action and, for public source, a file and line.
- Snapshot
- The exact copy of the repository that was scanned. Links to GitHub open the current version, which may have changed since.
- Complete / partial selection
- Large repositories are read within limits. A report says how many of the eligible files were read, and whether that was the whole selection.
- Entity trust
- The pillar for domain control, HTTPS and privacy and terms links. It is checked by Metal Mantra, not claimed by the repository.
- Domain verified
- You proved control of a domain by publishing a DNS TXT record. It does not prove you own the repository or that the code is secure.
- CI-attested
- A private repository's report, produced by running our scanner in the owner's own GitHub Actions. We never see the source.
- Endpoint only
- A report built from a public agent card, with no source inspected. Fewer pillars are scored and the grade stops at BBB.
- Re-audit pass
- A one-time $29 purchase that adds three re-scans to one repository.
- Credit
- One re-scan you can still use on a repository. Credits belong to your account and show on the Account page.