ECZ-ID Agent Trust · VS Code
See what your agent can reachbefore you let it act.
A free, local-first VS Code extension that reads what each agent in your workspace actually declares — tools, environment key names, framework surfaces, the MCP servers it can reach — and reports what changed between scans. Nothing leaves your machine.
Free forever, no account. Also on Open VSX · Already purchased? Activate
Local-first visibility. No sign-in.
or £119/year. History, deeper analysis, authority graph.
Developer Trust Pro — MCP + Agent — £19.99/month or £199/year. Compare →
The problem
Configuration is readable. Reach is not.
Everything below is visible in principle and invisible in practice, because nothing in the editor puts it in one place.
Declared tools are not the whole reach
An agent’s real authority is its tools plus the MCP servers in the same workspace plus the credential names it is handed. Read separately, each looks reasonable.
Capability chains hide between findings
Credential access is fine. External send is fine. Credential access followed by external send is the thing you wanted to catch, and a per-finding list will never show it.
Permission creep is invisible
Agent surfaces gain tools and reach over time. Without retained snapshots you cannot answer the only question that matters at review: what changed?
What you get back
Agent X-Ray and change detection, free.
A scan you run inventories each agent surface and tells you what moved since last time. Posture is neutral — there is no acceptable/unacceptable verdict.
- Per-agent inventory (Agent X-Ray). Content-inspects JSON agent surfaces (manifests, tool/action specs, ecz-agent.json) into a per-surface inventory. YAML and other formats are honestly labelled observed-by-filename-only.
- Declared tool visibility. Lists the tool / function / action names an agent surface declares.
- Environment key-name exposure. Environment variable NAMES only — values are never read into results. Credential-shaped names are flagged.
- Workspace MCP relationships. Surfaces the MCP servers declared in the same workspace. Per-agent binding is not asserted.
- Change detection. One local baseline per workspace; the next scan reports tools, env key names, frameworks and MCP relationships that changed.
- Workspace Trust enforced. In Restricted Mode no workspace file is scanned or read.
ECZ-ID Agent Trust - 2 agent surfaces - agent.yaml ........... no ecz-agent.json reference found yet - mcp tool config ...... resolver reference present Posture: neutral - local policy decides, re-check before reliance
Verbatim output from the shipped extension. Environment variable values are never read into results.
In under a minute
Install, scan, re-scan before you grant access.
No account, no agent framework to adopt, no manifest to write first.
- 1
Install and open your project
Install free from VS Marketplace or Open VSX, open a workspace and trust it. There is no sign-in and no account.
- 2
Run Scan Workspace
Agent manifests, framework configs, tool specs and MCP tool configuration are inventoried per surface — tool names, environment key names, framework labels.
- 3
Re-scan before you grant access
One local baseline per workspace means the next scan reports precisely which tools, keys, frameworks and MCP relationships moved.
Agent Trust Pro
The whole reach, not a list of declarations.
Everything below is computed locally from discovered evidence, and every node and edge shows the evidence it came from.
Authority Graph
Every agent, tool, MCP target, API origin, credential key NAME, declared permission and capability signal in one graph. Each node and edge carries the evidence it came from. No trust score is computed.
Dangerous action chains
Deterministic indicators for chains such as credential access to external send, filesystem access to network send, package mutation to deployment. Each shows its nodes, reason, evidence and a remediation suggestion.
Authority Epochs
Retained local snapshots, compare any two: added or removed authority, permission expansion, new MCP references, new API origins, new credential-key exposure, new destructive capability.
Reachability
What an agent can actually get to, read as reach rather than as a list of declarations — because the declarations only mean something together.
Credential-key-name analysis
Which credential-shaped names each surface is handed, and when that set changes. Names only, never values.
Reciprocal Agent-to-MCP view
The same relationship read from both ends, with truthful coverage. "ENFORCED VIA LOCAL TRUST GATE" is shown by ECZ-ID MCP Trust when it holds a live gate session; Resolver public proof stays separate.
Free vs Pro
Pro adds. It never takes anything away.
If a Pro subscription lapses, only the Pro features deactivate — Community keeps working and your locally retained history stays.
| Capability | Community | Agent Trust Pro |
|---|---|---|
| Agent surface discovery and per-agent X-Ray | Full | Full |
| Declared tool names and environment key NAMES | Full | Full |
| Workspace MCP relationships | Full | Full |
| Change since your previous scan | One baseline | Full history, compare any two |
| Authority Graph across tools, MCP targets and credential names | — | Yes |
| Dangerous action-chain indicators | — | Yes |
| Authority Epochs with retention you control | — | Yes |
| Reciprocal Agent-to-MCP view | — | Yes |
| Remediation with diff, apply and rollback | — | Yes |
| Exportable local evidence reports | — | Yes |
| Runs with no account, no telemetry, nothing uploaded | Always | Always |
Plans
Start free. Upgrade when reach matters.
Agent Trust Community
- •Per-agent inventory (Agent X-Ray)
- •Declared tool visibility
- •Environment key-name exposure
- •Workspace MCP relationships
- •Change detection
Agent Trust Pro
- •Everything in Community
- •Authority Graph — what every agent can reach, across its declared tools and the MCP servers in the same workspace
- •Action Chains — dangerous capability chains surfaced as chains, not as isolated findings
- •Authority Epochs — full history of how an agent’s reach changed, with exact diffs and your own retention
- •Reciprocal Agent-to-MCP view — the same relationship read from both ends
- •Remediation — preview, apply and roll back posture changes
- •Local evidence reports you can export and keep
Secure checkout by Shopify. Cancel any time. Already purchased? Activate here.
ECZ-ID Agent Trust is published on both registries. Install free, in your editor or from the web.
Activate the licence from your order confirmation. A Developer Trust Pro bundle key turns on both extensions.
Activate your purchase →Developer Trust Pro covers Agent Trust Pro and MCP Trust Pro on one licence key — £19.99/month or £199/year, less than the two Pro plans separately.
Free resource · 10 pages · no email required
Free Agent Authority Preflight
Know what an agent can reach before it acts. A practical, vendor-neutral checklist covering declared tools, credential-key exposure, MCP relationships, capability chains and the change review worth doing before you grant an agent access.
Runs with or without our extensions. Nothing to sign up for.
Questions
Before you install.
Does it run or call my agents?
No. It inspects local files only and never executes an agent, tool or webhook. Coverage is OBSERVED locally / UNMANAGED — Agent Trust does not mediate or enforce runtime agent execution.
Is the Authority Graph inferred or invented?
Neither. Every node and edge comes from deterministic discovered evidence and carries its source. An agent-to-MCP edge is drawn only when the agent’s declared server name also appears in the workspace MCP inventory. No trust score is computed.
Does a dangerous action chain mean my agent is malicious?
No. Chains are risk indicators derived from declared configuration, each shown with its nodes, edges, reason and source evidence so you can judge for yourself. They never declare an agent unsafe or malicious.
Is the free version time-limited or a trial?
No. Community is free permanently and needs no account. Pro adds to Community; it never removes anything. If a Pro subscription lapses, only the Pro features deactivate and your locally retained history stays where it is.
Does any of my code or configuration get uploaded?
No. No source, prompts, tool arguments, tool results or secret values leave your machine, and there is no telemetry. Results carry names, counts, states and local fingerprints only.
Does it read my environment variable values?
Never. Environment variable NAMES are inventoried so you can review intended exposure; values are not read into results, displayed, retained or transmitted. The posture fingerprint is deliberately invariant to secret rotation.
I already paid. How do I turn Pro on?
Use the activation page and paste the licence from your order confirmation. The bundle licence activates both extensions. Activation is verified locally with asymmetric cryptography and the token is never displayed or transmitted.
Can I cancel?
Yes, at any time, from your account. Checkout and billing are handled by Shopify; this site runs no checkout of its own.
ECZ-ID also publishes agent identity infrastructure — Agent Credential and KYA and the API Passport. Those are separate products; they are not what this extension does.
Free · self-service
Operate an MCP server or an agent? Give it an ECZ-ID Passport.
The extensions inspect systems from the outside — the position you are in when you consume someone else's server or agent. If you operate one, you are on the other side of that question, and the people evaluating you want something they can check without asking you. An ECZ-ID Passport establishes a reusable identity with a public presence on the Resolver.
- Free, fast self-service
- A reusable machine-readable identity, not a one-off badge
- Public, read-only Resolver presence others can check
Passport issuance is an ECZ-ID platform service, not a function of the VS Code extensions. The extensions inspect and route; they never issue proof themselves.
The ECZ-ID estate
These extensions are one surface of a machine-trust infrastructure layer.
Identity, public proof and verifiable posture for the systems that now call each other without a human in the loop.

