Metal Mantra / AGENT INTELLIGENCEPlain-language help · never certificationAUTOMATED SIGNAL. NOT CERTIFICATION.
01User guide

Start here

Metal Mantra is a public registry of AI agents. For each agent it shows what an automated scan found in the source, what the owner can prove about their domain, and what could not be checked.

There are two kinds of visitors, and you can be both.

Buyers
You want an agent for a job and need evidence beyond a README and a star count. You do not need an account to browse, search and compare. You need one only to vote.
Builders
You made an agent and want a public, readable report for it. You sign in, add your repository and your domain, and get a report you can share.
Which path fits you
Your situationUseEvidence it produces
Source is public on GitHubPublic scanStrongest. We read the source ourselves.
Source is private on GitHubCI attestationWeaker. You run our scanner; we cannot reproduce it.
No source, just a hosted agentEndpoint-onlyWeakest. Reads the agent card, grade stops at BBB.
Looking for an agent to useRegistry and matchingReports from all three, clearly labeled.
02User guide

Read a report in two minutes

Every public report is built the same way, so you can read any of them with the same four stops.

  1. Start here box

    The first thing on a report. It names the most serious finding, or says that no rule matched and that this still is not proof of safety. Beside it, a short note lists what the report does not establish.

  2. Findings

    Each finding has a severity, the rule that matched, an explanation, a suggested action and, for public source, a link to the file and line. Filter by severity or pillar. Open a few before you decide anything.

  3. Evidence and limits

    How many files were read, whether that was the whole eligible selection, and when. Domain checks (DNS, HTTPS, privacy and terms links) are shown here too. This is where the report says what it could not see.

  4. Score breakdown

    Each pillar's score and weight, so you can see exactly how the overall number was made.

The grade

AAA90 – 100

Few or no rule matches in what was scanned.

BBB70 – 89

Some matches. Read the findings.

CCCBELOW 70

Many or serious matches. Read before you buy.

A grade only compares reports made with the same method. Do not compare a v0.2 score with an archived v1 score.

The five pillars

25%Security and privacy
25%Guardrails and loop control
20%Schema and tooling
15%Token and cost efficiency
15%Entity trust
  • Security and privacy: hardcoded secrets, running generated code, untrusted text in privileged prompts, user-controlled network destinations.
  • Guardrails and loop control: token ceilings, rate limits, loops that can run forever, sensitive actions without human approval.
  • Schema and tooling: model output validated at runtime, no raw text returned, citations for retrieval answers.
  • Token and cost efficiency: model fallbacks, caching, bounded history and input size.
  • Entity trust: domain control, HTTPS, and links to a privacy policy and terms.

How the number is made

Each pillar starts at 100. Every finding takes points off that pillar, more for serious ones. The overall score is the weighted sum of the five pillars.

Severity
SeverityMeaningTypical deduction
CRITICALCould let an attacker or a runaway process do real damage.18 – 22 points
MAJORA clear gap in a safeguard.10 – 16 points. Domain checks in Entity trust cost more: 25 – 50
MINORWorth tidying up, lower risk.8 – 15 points

Example: a guardrails pillar with an unbounded model loop (−22) and a request without a token ceiling (−12) scores 66 out of 100, and contributes 66 × 25% = 16.5 points to the overall score.

Labels you may see

LabelWhat it tells you
Public reportMade by Metal Mantra from public source and domain checks.
CI-attestedPrivate source. The owner ran our scanner in their CI. GitHub confirms which repository and commit ran, but we never saw the code.
…with pinned scannerAs above, but run through Metal Mantra's own reusable workflow, so the owner could not alter the scanner or the files it read.
Endpoint onlyNo source was inspected. Built from the agent card the owner publishes.
Archived v1An older method with four pillars. Not comparable with v0.2.
Domain verified at scanThe owner proved DNS control of the domain at the time of the scan. It is a statement about the scan, not about today.
Partial selectionThe repository was larger than the scan limits, so only part of it was read.
03User guide

Find and compare agents

Two ways in: describe the job and get suggestions, or browse the registry with filters.

Describe the job (home page)

  1. Open the home page and choose “Buy an agent”.

    Write what you need in your own words, up to 500 characters. Any language works.

  2. Optional: tick “Rank with AI”.

    Your description is sent once to our AI provider (Anthropic) to choose up to three agents, and is not stored. Without the box, matching runs in your browser tab only and nothing is sent.

  3. Read the results as leads.

    Each suggestion quotes a statement from the agent's own repository. That is what the repository claims, not verified job fit. Open “Inspect evidence” to read the full report. A framework may need development before you can use it.

If the AI option is unavailable, the page falls back to keyword matching and says so.

Browse the registry

Open Agent registry. Search by agent or builder name, then narrow with the filters.

ControlWhat it does
MethodAgent Signal v0.2 or Archive v1. Choose one before you filter by grade.
GradeAAA, BBB or CCC for v0.2. Only available once you pick a method.
ScopeComplete selection means every eligible file was read. Partial means the repository was larger than the limits.
Topic (inferred)A category guessed from the repository's own text. It helps you browse and is not verified.
DomainShow only agents whose owner proved domain control at scan time.
SortLatest scan, Name, Score within method, Top this week (votes), or Recently pushed (last GitHub push).

Open “How results are ordered” on the page for the exact rules. No payment affects order.

Compare side by side

Tick up to three reports, then press “Compare reports”. You can only compare reports from the same method, because scores from different methods mean different things.

Votes

A vote shows community interest. It never changes a score or grade. To vote you must be signed in with an account at least 24 hours old, you can vote once per agent, up to 30 new votes a day, and you cannot vote for an agent you scanned. “Top this week” counts votes since Monday 00:00 UTC.

User reports

Under a report you can say whether the agent worked or failed for you, with a short note. Each report is one signed-in GitHub account's statement. We do not verify that the account ran the agent, and reports never change a score, grade or order. You need an account at least 24 hours old, you can add one report per agent (and change or remove it), and notes are plain text with no links. You cannot report on an agent you scanned, but you can reply to reports on it. For a security problem, use the disclosure page instead of a public note.

Ask Claude or ChatGPT

The registry can be added as a read-only connector, so an assistant can search it, read a report and check an agent before you rely on it. No sign-in is needed. The address is https://metalmantra.io/mcp.

  1. Add it as a custom connector.

    In Claude, open Settings, then Connectors, then add a custom connector with that address. In ChatGPT, add it as a connector in developer mode with the same address and no authentication.

  2. Ask in plain words.

    For example: “Find an agent that triages support tickets, then check whether it meets a score of 80.” The assistant calls search_agents, get_agent_report and verify_trust.

  3. Read the verdict as a lead.

    unknown means the agent has not been checked, never that it is safe. Text quoted from a repository is passed along as data, not as instructions. Results are automated signals, not a certification.

Visit vendor site

The link appears only when the agent was scanned and its owner verified the domain by DNS. We re-check weekly and hide the link if the record is gone. Links are not for sale. For a CCC grade or a critical finding, a caution appears beside the link: read the report before you buy.

04User guide

Scan a public repository

Your first scan is free. The report is public the moment it finishes.

Before you start

  • The repository is public on GitHub and contains an AI agent (a model call with tool use, an agent framework or an agent loop). Generic SaaS code is not accepted.
  • The code is JavaScript, TypeScript or Python.
  • You know the official domain of the agent, for example example.com.
  • You can sign in with GitHub or ChatGPT.
  1. Open Scan and sign in.

    GitHub sign-in asks only to read your public profile and email. It does not request access to your repositories.

  2. Paste the repository URL and the domain.

    Use the form https://github.com/owner/repo. An unverified domain is allowed, but it is clearly marked and costs points in Entity trust.

  3. Tick the consent box.

    It confirms you understand that the first report is public immediately and may contain redacted findings.

  4. Press “Run scan and publish report”.

    We download a snapshot, apply the rules, check the domain, and take you to the public report. Do not close the tab while it runs.

  5. Read your report, then fix and verify.

    Use the suggested actions to improve the code, and verify your domain to unlock one free re-scan.

What gets read

LimitValue
File types.js .jsx .mjs .cjs .ts .tsx .py
Files per scanUp to 80, each up to 120 KB, 4 MB in total
Download sizeRepository archive up to 12 MB
Skippednode_modules, vendor, dist, build, tests, minified and type-definition files
OrderProduct source first (src, lib, app, server), then other files, then examples, docs and tooling

If a repository is bigger than the limits, the report says it is a partial selection and shows how many files were read.

After the scan

  • Critical findings are hidden from public view for 30 days. You see them in full in your private report under Your account.
  • Metal Mantra does not promise to notify maintainers before details are revealed. If a finding is wrong or sensitive, use the support form early. See the disclosure note.
  • Scanning does not prove ownership. Disputes about who controls a repository go to support.
05User guide

Verify your domain

Verification proves you control the domain you named. It raises the Entity trust pillar and unlocks a free re-scan.

  1. Open your private report.

    Go to Your account, find the agent and choose “Open private report”. Scroll to “Your evidence workspace” and “Verify domain control”.

  2. Copy the DNS record shown there.

    You will see a Name and a Value. They look like this, with your own domain and token:

    Type TXT Name _metalmantra.example.com Value metalmantra-verification=<your-token>
  3. Add it at your DNS provider.

    Some providers want only _metalmantra as the host, because they add your domain for you. Paste the value exactly, without extra quotes or spaces.

  4. Wait, then press “Check DNS record”.

    DNS can take a few minutes or longer to spread. If it says the record was not found yet, wait and try again.

  5. Run a new scan.

    Verification does not change an existing score. Your first successful verification gives you one free re-scan so the new evidence can be included. Use “Start a new scan” in the same workspace.

Records created under our earlier name (_gaaas) still work.

06User guide

Re-scans, credits and payment

Re-scan after real changes to code or controls. A new scan creates fresh evidence; it never rewrites an old report.

What you get
ItemPriceWhat it gives
First scanFreeOne public report for a supported repository.
First DNS verificationFreeOne free re-scan, once per repository.
Re-audit pass$29, one timeThree re-scans for one repository. No subscription or auto-renewal.
OrganizationCustomFor teams with several agents. Talk to us through support.

Buy a re-audit pass

  1. Finish your free scan first.

    Passes are for repositories you have already scanned.

  2. Start another scan on Scan.

    When no credits are left you will see “A re-audit pass is required”, with a “Buy a re-audit pass” button.

  3. Pay on the secure checkout page.

    Payments are handled by Dodo Payments, which acts as Merchant of Record: it charges you, collects tax and sends your receipt. Metal Mantra never sees your card details.

  4. Come back and scan.

    Credits arrive as soon as the payment is confirmed, usually within seconds. They appear under “Credits and purchases” on Your account.

Refunds

  • If you have not used any of the three re-scans, you can ask for a full refund within 14 days of purchase through the support form.
  • After a re-scan from the pass is used, it is not refundable, except where the law requires it or a re-scan failed because of a fault on our side.
  • An approved refund removes the unused credits. A refund does not change a published report.
07User guide

Private repository: publish from your own CI

For commercial agents whose source is not public. You run our scanner inside your GitHub Actions and we publish the result. Your code never leaves your runner.

  1. Register your repository on Scan / Private.

    Sign in, then enter the private repository URL and your official domain. The repository must be private or internal. If it is public, use the normal scan instead.

  2. Copy the workflow we give you.

    It is a short GitHub Actions file with your registration id inside. The registration id is not a secret.

  3. Commit it to your repository.

    Save it as .github/workflows/scan.yml. It runs on pushes to main, weekly on Mondays at 06:00 UTC, and whenever you start it by hand.

  4. Run it once from the Actions tab.

    Choose “Metal Mantra agent signal” and press “Run workflow”. The log shows exact file locations for your own use.

  5. Your report goes public after the first successful run.

    Find it in the registry, labeled CI-attested.

What leaves your runner

  • Only rule ids and how many times each matched, plus file counts and the commit. No paths, no lines, no excerpts, no code.
  • GitHub signs a short-lived identity token that proves which repository and commit made the request. We check it, rebuild every finding from our own rule list, and compute the domain evidence ourselves.

Rules to know

  • Only pushes, scheduled runs, manual runs and releases publish. Pull request runs never do.
  • One report per registration every 10 minutes. No credits are needed, because you pay for the compute in your own CI.
  • You cannot take over a profile owned by another account, and a deleted or transferred repository cannot reuse an old registration.
08User guide

Hosted agent with no code to share

If your agent is a hosted service, we can read the public agent card on your domain and publish a limited signal.

What you need

  • A domain you control.
  • An A2A-style agent card at https://your-domain/.well-known/agent-card.json (or agent.json in the same folder). It must have a name and list skills or capabilities. A generic website is rejected.
  1. Open Scan / Endpoint and sign in.

    Enter your domain and press “Check and publish”.

  2. Add the DNS TXT record it shows.

    The first press returns a record to add, in the same format as domain verification. This proves you control the domain.

  3. Press “Check again”.

    We fetch your card, score it and publish the report. We re-check DNS on every publish, so a record you remove later stops working.

What is scored

ScoredNot assessed
Security and privacy: declared authentication, HTTPS, interfaces on the same domainGuardrails and loop control
Schema and output: skills, descriptions, input and output modesToken and cost efficiency
Entity trust: provider, version, documentation, plus our own DNS, HTTPS and policy-link checks

Weights are rescaled over the three scored pillars, and the grade cannot go above BBB, because a card is a claim and not behavior. The report says so on its face.

  • One check per agent every 10 minutes.
  • We only fetch the fixed well-known paths on your verified domain, over HTTPS, with a 256 KB cap and a six-second timeout.
  • If you later have a repository we can read, a normal scan gives a stronger signal.
09User guide

Account and sign-in

Sign in with GitHub or ChatGPT. GitHub sign-in asks only for your public profile and verified email and never for repository access. Matching verified emails are joined into one account. A sign-in lasts 30 days, and you can sign out any time.

Your private Account page shows:

Your agents
Every repository you scanned, with grade, score, visibility and domain status. “Open private report” gives you the owner workspace with full details and DNS verification. “View public page” opens the public report.
Credits and purchases
Re-scans left per repository and your recent purchases with their status.
Support requests
What you sent and whether it is open or resolved.
Sign-in
Your email, linked providers and a sign-out button.

Only you can see this page.

10User guide

Share a report and add a badge

Every public report has a “Copy report link” button. Share the report itself so its scope and limits travel with the score.

You can also embed a badge. Replace owner/repo with your repository:

[![Metal Mantra signal](https://metalmantra.io/api/v1/badge/owner/repo.svg)](https://metalmantra.io/agents/owner/repo)

The badge shows your grade, score, whether your domain was verified, and the date of the scan. It updates when you re-scan, and after 90 days without a re-scan it marks itself STALE, because the code may have changed. Link it to the report. Please do not describe it as a certification, because it is not one.

11User guide

When something goes wrong

Messages you may see
MessageWhat it meansWhat to do
Only public GitHub repositories are supported. / Repository not found or not public.The URL is wrong, or the repository is private.Check the URL. For a private repository, use the CI route.
No autonomous agent runtime or tool-calling evidence was found…The code does not look like an AI agent. This registry accepts agents, not general SaaS.Scan the repository that holds the agent's loop or tool calls.
No supported source files were found in this repository.There is no JavaScript, TypeScript or Python source in the files we can read.Scan the repository that contains the agent code.
Repository archive is too large for the free scan.The download is over 12 MB.Scan a smaller repository or contact support.
Daily scan limit reached. Try again tomorrow.You used today's 5 scans, including failed ones.Wait until tomorrow.
A re-audit pass is required for another scan.You have no credits left on this repository.Verify your domain for one free re-scan, or buy a pass.
This repository's re-audit pass belongs to another account.A different account scanned this repository first.Contact support to sort out ownership.
GitHub took too long to respond. Try again.GitHub was slow.Try again in a minute.
TXT record not found yet.The DNS record has not spread, or the value does not match.Check name and value, wait, then check again.
This agent was checked a few minutes ago.Endpoint and CI reports are limited to one every 10 minutes.Wait ten minutes.
This agent profile belongs to another account.Someone else already published this agent.Contact support with proof of control.

Other things

  • No “Continue with GitHub” button. Use “Continue with ChatGPT”. Both reach the same features.
  • Vote button does nothing. Your account may be under 24 hours old, or you scanned that agent yourself, or you reached 30 votes today.
  • A report looks wrong. Use “Report a problem with this report” at the bottom of the report. It fills in the report for you.
  • Your form was lost after sign-in. The scan form remembers the repository and domain in your browser tab. Open the form again in the same tab.
12User guide

Get help

Use the support form. Pick the topic that fits and include the report URL.

TopicUse it for
A scan or reportA wrong finding, missing evidence, a scan that failed.
Repository claim or ownershipYou maintain a repository someone else scanned, or a pass is tied to the wrong account.
Privacy or data requestAccess, correction or removal of your information.
Security disclosureA vulnerability in Metal Mantra itself, or a sensitive finding.
Account accessSign-in problems, refunds and purchases.

Prefer email? hello@metalmantra.io for general questions, security@metalmantra.io for security, privacy@metalmantra.io for privacy. Never send passwords, private keys or exploit details.

Common questions

Does a high grade mean an agent is safe?

No. A grade summarizes what automated static checks found in a bounded snapshot of source. It says nothing about how the agent behaves in production, how it is configured, or whether it fits your job. Treat it as a reason to look closer, never as a certificate.

Does an empty findings list mean nothing is wrong?

No. It means none of the rules matched inside the files that were scanned. Unscanned files, dependencies, runtime configuration and real behavior are all unknown.

Can I scan a repository I do not own?

The scan itself does not check ownership, so anyone signed in can scan a supported public repository. That is why the report says so plainly: starting a scan does not prove you maintain the code. If a maintainer disagrees with a report, they can ask for a correction through the support form.

Why were critical details hidden on a report?

For the first 30 days after a scan, public views replace the title, description, fix and source location of critical findings with a notice. The score and the other findings stay visible. The owner sees everything in their private report. After 30 days the details may be revealed automatically.

Why can't I sort by stars?

Stars are easy to buy and measure fame, not quality. The registry shows them for context only and never uses them to order or score agents.

Can I pay to improve my score or my ranking?

No. Payment buys extra re-scans only. It never changes a score, a grade, the order of the registry or whether a vendor link is shown.

13User guide

Glossary

Agent Signal v0.2
The current method: five weighted pillars scored from source and domain evidence. It is the only method new scans use.
Archive v1
An earlier four-pillar method. Old reports stay readable, but their scores cannot be compared with v0.2.
Pillar
One of the five areas scored in a report: security and privacy, guardrails, schema and tooling, cost efficiency, and entity trust.
Finding
One place where a rule matched. Each has a severity, an explanation, a suggested action and, for public source, a file and line.
Snapshot
The exact copy of the repository that was scanned. Links to GitHub open the current version, which may have changed since.
Complete / partial selection
Large repositories are read within limits. A report says how many of the eligible files were read, and whether that was the whole selection.
Entity trust
The pillar for domain control, HTTPS and privacy and terms links. It is checked by Metal Mantra, not claimed by the repository.
Domain verified
You proved control of a domain by publishing a DNS TXT record. It does not prove you own the repository or that the code is secure.
CI-attested
A private repository's report, produced by running our scanner in the owner's own GitHub Actions. We never see the source.
Endpoint only
A report built from a public agent card, with no source inspected. Fewer pillars are scored and the grade stops at BBB.
Re-audit pass
A one-time $29 purchase that adds three re-scans to one repository.
Credit
One re-scan you can still use on a repository. Credits belong to your account and show on the Account page.