Find and fix reliability and safety gaps in agent code, across nine agent SDKs.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Find and automatically fix guardrail gaps, unsafe tools, missing validation, and unbounded loops in Claude Agent SDK, OpenAI Agents SDK, Google ADK, LangChain, CrewAI, and MCP agents β before production.
Find what will make your AI agent fail β then fix it with one command.
Trustabl scans an agent repository for the gaps that break agents in production: tool descriptions too vague for a model to know when to use them, missing retry and timeout handling, untyped parameters, absent guardrails, and tool grants that exceed what the agent claims to do. Then it applies the fix directly to your source.
Every other agent scanner hands you a report. Trustabl hands you a patch.
Reliability is engineered before deployment, not observed after it.
Scanning runs entirely on your machine. No cloud scanner, no account, no code upload, no LLM β deterministic static analysis.
9 SDKs Β· 7 languages Β· human, JSON, or SARIF 2.1.0 output Β·
CI-friendly exit codes Β· also runs as a local stdio MCP server (trustabl mcp).
Deepest coverage for Claude Agent SDK, OpenAI Agents SDK, Google ADK, and MCP servers. Also scans LangChain / LangGraph, CrewAI, AutoGen / AG2, Pydantic AI, and the Vercel AI SDK β see COVERAGE.md for the full matrix.
Scanning needs no key and no network. Applying fixes uses your own Anthropic, OpenAI, or Google key.
Real output, scanning an agent repo that ships a Claude Agent SDK client, an MCP server, a subagent, and two skills:
Three things worth noticing:
skill:action-creator at 45% tells you where to look first.trustabl enrich --apply writes those fixes to source.0 when nothing reaches medium severity,
1 when something does, so a pipeline can stop a bad agent from shipping.The failures are rarely exotic. They are the same handful of gaps, over and over:
Bash despite a read-only descriptionEvery one of these is visible in the source before the agent ever runs. Trustabl finds them in seconds, offline, with no LLM β and fixes them.
The rest of this document explains what Trustabl reasons about and how the scan works, then covers building and running it. For the full implementation reference see ARCHITECTURE.md; for the at-a-glance SDK coverage matrix see COVERAGE.md.
Trustabl does not treat a repository as one undifferentiated blob. Every rule is classified into exactly one of five scopes, and each scope receives a different typed input:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/trustabl)<a href="https://allmcps.com/mcp/trustabl"><img src="https://allmcps.com/api/badge/trustabl?style=directory" alt="Trustabl on AllMCPs" /></a>