Know what your agents can do — before you let them act.
ECZ-ID Agent Trust is a free, local-first VS Code extension: a per-agent inventory of declared tools, environment key names and framework surfaces, the MCP servers your workspace declares, and change detection between scans.
What the free extension does
Current Community capability. JSON agent surfaces are content-inspected; YAML and other formats are honestly labelled observed-by-filename-only.
Per-agent inventory (Agent X-Ray)
Content-inspects JSON agent surfaces (manifests, tool/action specs, ecz-agent.json) into a per-surface inventory. YAML and other formats are honestly labelled observed-by-filename-only.
Declared tool visibility
Lists the tool / function / action names an agent surface declares.
Environment key-name exposure
Environment variable NAMES only — values are never read into results. Credential-shaped names are flagged.
Workspace MCP relationships
Surfaces the MCP servers declared in the same workspace. Per-agent binding is not asserted.
Change detection
One local baseline per workspace; the next scan reports tools, env key names, frameworks and MCP relationships that changed.
Workspace Trust enforced
In Restricted Mode no workspace file is scanned or read.
Enforced privacy mode
local-only (default) opens the public check with no detected metadata; metadata-only encodes filename/classification metadata only, disclosed before anything opens.
ecz-agent.json validate / scaffold
Validates or scaffolds a local ecz-agent.json only when you ask; modal-consented writes.
Local-first processing
No source, prompts, tool arguments, tool results or secret values leave your machine. No telemetry.
Agent Trust does not claim to be certified, safe, approved, or to provide runtime mediation or enforcement. It reports what it observed locally.
Plans
Agent Trust Community
- •Per-agent inventory (Agent X-Ray)
- •Declared tool visibility
- •Environment key-name exposure
- •Workspace MCP relationships
- •Change detection
Agent Trust Pro
- •Everything in Community
- •Planned: Authority graph across agents and their tools
- •Planned: Dangerous-capability-chain review
- •Planned: Custom local policy and richer history
Paid plans are not yet enabled. Community is fully usable today.
Pro features are planned and clearly not yet active. Community is fully usable today.
Adjacent ECZ-ID infrastructure
Separate, optional products for when you need a resolver-verifiable agent identity others can check — not the same thing as Agent Trust Pro. The extension inspects and routes; these carry canonical identity and proof.
ECZ-ID Agent Credential™
A resolver-verifiable reference for one logical agent, bound to an accountable operator. Acquisition and lifecycle live in TrustOps; current proof lives in Resolver. Agents & KYA hub →
ECZ-ID API Passport™
A resolver-verifiable reference for one authorised API surface. API Passport docs →
