Community updates and contributor highlights: AgenTrust on LinkedIn.
This repository is where you try the AgenTrust projects and connect them to the tools you already use. It holds runnable examples, short demos, and integrations: small pieces of code that link a product or agent framework to cMCP (rule checks on an agent's tool calls), cA2A (checkable handoffs of work between agents), TRACE (signed receipts of what an agent did), Agent Manifest (a signed record of how an agent is set up) and WCM (model-weight keys released only to checked hardware). Vendors and community projects add their own integrations here under published rules, while the core repositories hold only first-party code. New to the terms? See the plain-terms list.
Sponsors are listed in SPONSORS.md. Sponsorship has no effect on marketplace listings, verification tiers, who maintains the repository, or how the project is run.
| Location | What belongs there | Who contributes |
|---|---|---|
| cmcp, agent-manifest, trace-spec, TRACE conformance | The standard and reference implementation. Bug fixes and spec feedback welcome; no vendor product code. | Maintainers; community fixes |
| examples/ | First-party, end-to-end runnable examples, plus flagship partner examples by invitation. Every line is reviewed and every claim verified before merge. | Maintainers; invited partners |
| integrations/ | Your product's integration with cMCP, TRACE, or Agent Manifest: adapters, exporters, dashboards, policy packs, verifiers. Vendor-maintained. | Anyone, self-serve |
| awesome-ai-governance | Neutral listings of notable agent-governance tools, including ones that do not integrate with this stack. | Anyone meeting the listing criteria |
| demos/ | Short runnable demonstrations and the browser console, using the examples in this repository. | Maintainers; reviewed contributions |
- Examples: complete scenarios and offline evidence verification.
- Demos: short demonstrations and the browser console.
- Integrations: adapters and vendor-maintained connections.
See CONTRIBUTING.md for the review rules for each directory. Existing adapter and package paths remain supported. Examples retain Apache-2.0; demos retain MIT.
Every listed integration has a tier that tells you how much we checked it.
Community - we checked the structure and listed it. The directory follows the layout, the manifest is valid, the links work, and the description makes no claim we can show to be false. We do not run your code, and the listing says exactly that.
Verified - everything above, plus we ran the integration end to end against released packages and confirmed it does what its README says. Verified integrations get the badge in the index and can be listed on the awesome list. Ask for verification in your PR; we check again at every release that touches your integration.
Tier is recorded in each integration's integration.yaml and is set by maintainers, never self-declared.
TRACE only works as a standard if it is genuinely neutral. Integrations are listed on technical merit under the same rules for everyone, including products that compete with anything we build. A submission is declined for unverifiable claims, misrepresentation, or marketing written as documentation, and never because of who sent it. See CONTRIBUTING.md for the precise rules.
| Integration | Vendor | Integrates with | Tier |
|---|---|---|---|
| claude-code | agentrust-io | agent-manifest, trace | community |
| Agent Passport System | aeoess | trace | verified |
| cA2A Cross-Operator Delegation | agentrust-io | ca2a | community |
| Confidential Workflow Acceptance Harness | agentrust-io | cmcp, ca2a | community |
| Agent Replay | Altru.dev | trace | verified |
| Frequency Agent Execution Assurance | Altru.dev | trace | community |
| Bernstein MCP verifier | Bernstein | trace | verified |
| CHAP | agentrust-io | trace | verified |
| AI Agent Incident Register | CompanyScope | agent-manifest | verified |
| comply54 | comply54 | trace | community |
| ComputeID AgentPassport TRACE Adapter | ComputeID | trace | community |
| DecisionAssure | DecisionAssure (a1k7) | trace | community |
| Docker Sandbox Kit | agentrust-io | trace | community |
| EPI Recorder | EPI Labs | trace, wcm | verified |
| EvidenceBound Core | EvidenceBound | trace | community |
| Google ADK | agentrust-io | trace | verified |
| LangChain | agentrust-io | trace | verified |
| SOVP | Litzki Systems | trace | verified |
| LlamaIndex | agentrust-io | trace | verified |
| Nobulex | Nobulex | trace | verified |
| OntoGuard Decision Authorization | OntoGuard AI | trace | verified |
| OpenAI Agents SDK | agentrust-io | trace | verified |
| OpenShell TRACE Adapter | agentrust-io | trace | community |
| OpenTelemetry GenAI | agentrust-io | trace | community |
| Observed-effect references | probityai | trace | community |
| ramen-ai cMCP Adapter | ramen-ai | cmcp, trace | verified |
| SAGE AgenTrust Bridge | SAGE | cmcp, trace | community |
| Agent Sentinel | a1k7 | trace | community |
| Agentic SpendGuard | SpendGuard | trace | community |
| WCM Agent Manifest Binding | agentrust-io | wcm, agent-manifest | community |
| WCM Azure Secure Key Release | agentrust-io | wcm | community |
| WCM Confidential Containers Trustee | agentrust-io | wcm | community |
| WCM CycloneDX ML-BOM | agentrust-io | wcm | community |
| WCM GCP Confidential Space | agentrust-io | wcm | community |
| Hugging Face WCM Download Gate | agentrust-io | wcm | verified |
| WCM in-toto Attestation | agentrust-io | wcm | community |
| WCM Kyverno Policy Pack | agentrust-io | wcm | verified |
| WCM NVIDIA GPU Attestation | agentrust-io | wcm | verified |
| WCM OCI Referrer | agentrust-io | wcm | verified |
| WCM OpenTelemetry | agentrust-io | wcm | community |
| WCM Key Release to TRACE | agentrust-io | wcm, trace | community |
| WCM Triton Repository Staging | agentrust-io | wcm | verified |
| WCM Serving Guard for vLLM | agentrust-io | wcm | verified |
| agentrust-codex | agentrust-io | agent-manifest, trace | community |
| scheduled-agents | agentrust-io | trace | community |
For each agent framework, this table shows which adapter covers it, where the evidence comes from, which released version CI actually runs, and what the adapter can and cannot see.
| Framework | Adapter | Evidence source | Released framework exercised in CI | Evidence boundary |
|---|---|---|---|---|
| Google ADK | Google ADK | First-party BasePlugin lifecycle |
Yes - Google ADK 2.7.1 InMemoryRunner |
Callback-visible invocation, model, and available tool identity; no payloads, retries, agent graph, function-body execution, or policy enforcement |
| LangChain | LangChain | First-party BaseCallbackHandler callbacks |
Yes - LangChain Core 1.6.0 callback contract | Tool identity and outcome plus model identity; no chain topology or runnable state |
| LangGraph | LangChain | First-party LangChain callbacks propagated by the graph | Yes - LangGraph 1.2.11 StateGraph with a nested tool call |
Propagated tool callbacks; no nodes, edges, state transitions, checkpoints, or rollback decisions |
| LlamaIndex | LlamaIndex | First-party instrumentation or per-run workflow stream | Yes - LlamaIndex Core 0.14.24 FunctionAgent, Workflows 2.23.3 |
Workflow tool-request names and call-id fingerprints; explicit model identity; no arguments/results, completion claims, graph state, or policy enforcement |
| OpenAI Agents SDK | OpenAI Agents SDK | First-party TracingProcessor spans |
Yes - OpenAI Agents SDK 0.22.0 scripted model and tool run | Tool, handoff, agent, and MCP identity and order; no payloads, reasoning traces, guardrail outcomes, session state, or retries |
| Pydantic AI | OpenTelemetry GenAI | OpenTelemetry GenAI transcription | Yes - Pydantic AI 2.35.1 TestModel with a tool call |
Telemetry-reported model and tool identity; no payloads; absent gen_ai.tool.type is not inferred |
"Adapter exists" and "released framework exercised" are separate claims here.
First-party hooks (code that runs inside the framework itself) produce
self-origin records with no origin block. Records copied from telemetry are
weaker evidence and say so explicitly. Each adapter
README documents what its observation surface can support; a missing concept is
not inferred into the TRACE record.
The Copilot, Cursor, Windsurf and
Gemini CLI drift checks are intentionally outside this manifest
index: none of them emit TRACE or Agent Manifest today, so none can truthfully
select an integrates_with value from the current schema. See the note below.
Shadow AI Discovery is also standalone tooling outside the index and Marketplace. It scans enriched records against an agent-to-tools registry; it has no direct cMCP adapter and does not read or write Agent Manifest records.
All seven engines share agentrust-capture-core,
which owns fingerprinting, comparison, baseline sealing and the report honesty rules.
Adapters that build a Trust Record from evidence another system produced share
agentrust-trace-adapters. Records built through it
are always marked as coming from another system, software-only and unappraised
(origin.kind: third-party-control-plane, runtime.platform: software-only and
appraisal.status: none), so a consumer reads the weaker assurance from the record
itself rather than from a README. None of the three is a parameter you can change.
Note on the Copilot, Cursor, Windsurf and Gemini CLI entries. Each is a check that runs on pull requests rather than a hook in a developer's session, because all four agents' composition (the instructions, rules, skills and tools configured for the agent) lives in the repository rather than a developer's home directory. Each emits no TRACE record and no Agent Manifest, so each claims neither. None currently produces or consumes one of the supported AgenTrust artifacts or protocols, and asserting otherwise would be an unverifiable claim.
That is currently blocked on a spec question rather than on implementation, tracked
in agent-manifest#256.
TRACE describes an execution and these checks describe a composition, so a TRACE
record is the wrong artifact. Agent Manifest is the right one, but every level
requires artifacts.model_identity, and a repository cannot know the model: each
of these agents picks it at session time from the user's own plan and settings.
The same repository serves every model, with an identical contributed composition.
Manufacturing a model to satisfy the field would be exactly the kind of
unverifiable claim CONTRIBUTING.md rules out, so all four integrations ship
without one until the spec has a way to express a composition whose model is
unknowable at authoring time.
Questions, feedback, integration help: Discord.
Apache 2.0. Each integration directory may carry its own compatible license; the manifest declares it.