Skip to main content

trustpact

Behavioral trust scanner for MCP servers and AI agents.

Install

pip install trustpact

Usage

# Scan a server from the Smithery registry
trustpact scan "slack"

# Scan a local server spec (JSON)
trustpact scan server.json

# JSON output for CI/CD integration
trustpact scan server.json --json

# Show AEGIS scoring methodology
trustpact info

What It Does

TrustPact scans MCP server tool definitions for manipulation patterns and calculates a behavioral trust score using the AEGIS 5-dimensional model:

  • Trust Signals (35%) — metadata, documentation, authentication
  • Manipulation Risk (25%) — hidden instructions, poisoning patterns
  • Protection Level (15%) — auth, scope, licensing
  • Vulnerability Index (15%) — critical exposure surface
  • Context Modifier (10%) — runtime context signals

Attack Classes Detected

Class Description
SIREN Hidden instruction injection
PHANTOM Identity spoofing
HYDRA Coordinated Sybil attacks
MIRAGE Capability misrepresentation
LEECH Data/credential exfiltration
CHIMERA Code injection, safety bypass

Trust Tiers

Tier Score Meaning
SOVEREIGN 95+ Highest trust
SENTINEL 85+ Proven track record
MASTER 65+ Reliable
ADEPT 40+ Limited history
FELLOW 0+ New or unverified

License

Proprietary — ARQON GmbH (i.G.)

Links

Metadata

Release files for trustpact 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for trustpact 0.1.0
File Size Uploaded
trustpact-0.1.0.tar.gz 10.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for trustpact 0.1.0
File Interpreter ABI Platform
trustpact-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 23.3 kB

Release files / trustpact-0.1.0.tar.gz

Download URL trustpact-0.1.0.tar.gz
Size 10.9 kB
Tags Source
SHA-256 checksum
How to use checksums
c24f9fbfe409e55330eac1419651e801990cdf1c15d17b3e94256b4822ed1025
BLAKE2b-256 checksum
How to use checksums
0b3cba246ca49710f032e67c7912800884ce06dbdb3adae1c9def8b86b416d3f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.2

Release files / trustpact-0.1.0-py3-none-any.whl

Download URL trustpact-0.1.0-py3-none-any.whl
Size 12.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b05729228a32d8f556fc5e34c94b2f6d0669afa71ef35aa3efdd5256b4e161d9
BLAKE2b-256 checksum
How to use checksums
22e89f65851bd194c788d0c7a2a2fcb23947e82c9e2a84657b96e3cdfbae3497
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.2

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page