Skip to main content

ECZ-ID AI Agent Inspection

ecz-id-agents statically inspects AI agent manifests for ECZ-ID configuration posture and declared relationships (tools, APIs, MCP servers, operator/principal). Part of the ECZ-ID PyPI family. It inspects, explains and routes only.

It never imports or executes agent code, never loads or runs agent tools, and never reads prompts into results — only their presence is noted, and redaction guards every export. It never issues or activates an ECZ-ID, never prices or carts, and never certifies. It is not a safety/compliance/insurance/premium decision and not a behavioural, alignment, capability or safety proof about the agent. Missing public proof is neutral. Local policy decides. Re-check before reliance.

One-command first run

$ ecz-id-agents inspect ./my-agent
ECZ-ID inspection: ./my-agent [ecz-id-agents]
A. configuration posture : PRESENT
B. public proof posture  : NOT_CHECKED  (neutral)
...
local policy decides; re-check before reliance

Supported inputs

  • A directory or manifest file. Recognised structured surfaces (static JSON only): agent_manifest.json, agent.json, agents.json, A2A Agent Cards (.well-known/agent-card.json, .well-known/agent.json), ecz-agent.json (and .well-known/), and agent-plugin descriptors (ai-plugin.json, agent-plugin.json).
  • Prose surfaces — AGENTS.md and SKILL.md — are recorded by presence and location only. Their content is instruction text written for an agent, so it is never opened, never parsed and never summarised into a result.
  • Observes declared agent name, model provider, tool / API / MCP / package / repository relationships and the declared operator / principal.

Evidence classes

Discovered facts are kept in separate classes so one can never be read as another:

Class What it records Established by this file alone?
IDENTITY who the agent claims to be No
OPERATOR who claims to run it No
AUTHORITY what it claims it may do No
INSTRUCTIONS prompt / skill surfaces (presence only) n/a
CAPABILITY declared tools, MCP servers, APIs, skills observation
CREDENTIAL credential-shaped key names only observation

These files do not establish verified identity, operator or authority. They record what a subject declares about itself; independent proof is a separate step, and the Resolver remains the read-only source of public proof. Credential posture is key names only — values are never read into a result.

Runtime object inspection (adapter boundary)

For OpenAI Agents, Pydantic AI, LangGraph and CrewAI, you may pass an already-constructed object and get neutral observations back — attributes are read, never called, the framework is identified without importing it, tools are not executed, and prompts are never inlined:

from ecz_id_agents import inspect_agent_object

report = inspect_agent_object(my_agent)   # {"observations": [...], "note": "..."}

Privacy boundaries

Static JSON inspection; never imports or executes agent code. Bounded, symlink-refusing enumeration. No telemetry, no uploads. Prompts are never inlined; secrets redacted on every export. Offline mode (--offline / ECZ_ID_OFFLINE=1) skips all network.

Explicit non-claims

Not a safety / certification / compliance / insurance / premium decision. Not a behavioural, alignment, capability or safety proof. Does not issue, activate or bind an ECZ-ID. Does not upload prompts. Does not price or cart.

Python API

from ecz_id_agents import inspect

result = inspect("./my-agent")
print(result.configuration_evidence.posture.value)   # PRESENT / PARTIAL / ABSENT / INVALID

CI / test example

$ ecz-id-agents inspect . --json > ecz-id-agents.json   # exit 0 for any completed inspection
$ ecz-id-agents doctor --json

Routes

Agent Credential and Know-Your-Agent guidance is arranged via TrustOps — this package only routes you there.

Re-check

$ ecz-id-agents recheck ./my-agent --json

Machine-readable integration

Machine Interface · Manifest · Resolver · Operator setup · Developer guidance

Each installation includes structured machine-readable metadata for automation, CI and supported integrations. Every JSON report embeds a compact machine_interface object with the canonical roots and safe, read-only actions.

The package runs locally to inspect, explain and route. It does not issue an ECZ-ID, write canonical truth, create public proof, price a cart, or replace Resolver proof.

$ ecz-id-agents manifest --json
$ ecz-id-agents compare ./old ./new --json    # neutral drift
$ ecz-id-agents inspect . --sarif             # SARIF for code scanning
$ uvx ecz-id-agents inspect .                 # or: pipx run ecz-id-agents inspect .

Need help choosing the right ECZ-ID route?

Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance

Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.

Continue with ECZ-ID

Licence and trademarks

Apache-2.0 (see LICENSE, NOTICE). The code licence grants no trademark rights; “ECZ-ID” and “EcoCitizenz” are trademarks of their owner(s) — see TRADEMARKS.md. Changelog: CHANGELOG.md. Security: SECURITY.md.

CLI: ecz-id-agents  |  Import: ecz_id_agents  |  Plugin group: ecz_id.plugins

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ecz_id_agents-0.2.0.tar.gz (20.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ecz_id_agents-0.2.0-py3-none-any.whl (20.2 kB view details)

Uploaded Python 3

File details

Details for the file ecz_id_agents-0.2.0.tar.gz.

File metadata

  • Download URL: ecz_id_agents-0.2.0.tar.gz
  • Upload date:
  • Size: 20.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for ecz_id_agents-0.2.0.tar.gz
Algorithm Hash digest
SHA256 39c084f542663fbe0de8404cc50942d409e64ddd52ad1a5a2bebe6675ac136f7
MD5 30b72e28adb8cc83e5738f5c3e541d6f
BLAKE2b-256 f313c97f60851846c126848745d203e3e7597b3c146d7b6fd781161aa77943b4

See more details on using hashes here.

Provenance

The following attestation bundles were made for ecz_id_agents-0.2.0.tar.gz:

Publisher: publish-ecz-id-agents.yml on Ecocitizenz/ecz-id-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ecz_id_agents-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: ecz_id_agents-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 20.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for ecz_id_agents-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2498dfa1609b56d23a2f4e1c4085b875783cef1fc0f35506560fe2f15e1b89b2
MD5 a2c8420800cae560bc1ee723b3700690
BLAKE2b-256 df5bca0ccd653a8c9f6d28e1a7b8357489dc56aed19c5cdd469b32e92f2ab11b

See more details on using hashes here.

Provenance

The following attestation bundles were made for ecz_id_agents-0.2.0-py3-none-any.whl:

Publisher: publish-ecz-id-agents.yml on Ecocitizenz/ecz-id-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page