ECZ-ID
Choose and run the right ECZ-ID workspace trust check from one place.
Free, local-first. No source upload. No sign-in to run a check.
- One cockpit that routes your workspace across the core ECZ-ID trust checks — agents, MCP, API, CI/CD, dependencies, compliance and vendors.
- Installing the Hub brings the full sixteen-specialist ECZ-ID estate; run
ECZ-ID: Show All Specialists to see everything installed.
- “Which ECZ-ID check should I run?” routes you to the right area in one click.
- Local scan groups findings by area, in plain English, with claim-free next actions.
Useful for
Useful across many legitimate roles. Commonly used by:
- Engineering and platform teams with several trust surfaces in one repository
- Security reviewers and enterprise architects
- Operators coordinating checks across teams
- Anyone deciding which ECZ-ID check to run first
Relevant when a repository mixes agents, APIs, pipelines, dependencies and vendor evidence, an evaluator asks where to start, you want one cockpit before drilling into a specialist.
What you can do in under a minute
- Open or scan the workspace — run
ECZ-ID: Scan Workspace.
- Review findings in plain English — grouped, with neutral posture.
- Open Resolver guidance or continue supported setup where relevant.
What it looks for
- The core ECZ-ID trust areas present in your workspace (see the estate table below).
ecz-agent.json, ecz-mcp.json, mcp.json resolver references.
- Which specialist check is most relevant to what you actually have.
The core ECZ-ID cockpit areas
| Area |
Looks for |
| Agent Trust |
Agents, MCP tools, frameworks, ecz-agent.json |
| MCP Trust |
MCP servers, mcp.json, .vscode/mcp.json, ecz-mcp.json |
| API Security |
OpenAPI / Swagger, GraphQL, API routes |
| CI/CD Trust |
Pipelines, Dockerfiles, release provenance |
| Dependency Security |
Lockfiles and software bill of materials |
| Compliance Risk |
Operational-resilience and audit artefacts |
| Vendor Risk |
Vendor / supplier manifests, SDK configs |
Installing the Hub also brings the wider ECZ-ID estate — SBOM Readiness, DORA Readiness, Cloud Trust, Counterparty Trust, Robotics Trust and the insurance-readiness specialists — each also available standalone. Run ECZ-ID: Show All Specialists to see everything installed.
Example result
ECZ-ID - Workspace scan
Detected surfaces: 6 Findings: 3 Privacy mode: local-only
- Agent Trust ......... ecz-agent.json present, no public proof reference found yet
- API Security ........ openapi.json detected, review recommended
- Dependency Security . lockfile present, resolvable
Next: Open Resolver | Continue supported setup | Open Developer Gateway
What results mean
Results describe public-proof posture, never a safety, approval, certification or compliance verdict:
resolvable · partial public proof · no public proof reference found yet · review recommended · re-check before reliance · your local policy decides.
There is no “pass/fail”. Local policy decides what is sufficient, and you should re-check before reliance.
Recommended next steps
- Inspect the finding — plain-English detail, no verdict.
- Copy verification guidance — a claim-free snippet you can share.
- Open Resolver — read-only public proof lookup.
- Continue supported setup — hand off to TrustOps (metadata only).
- Open documentation — Developer Gateway.
- Re-check later — re-run before you rely on a result.
Privacy & permissions
| Question |
Answer |
| Files read |
Filenames and paths during a normal scan |
| File contents read |
No — except a file you explicitly target (e.g. an ecz-*.json you ask to validate) |
| Selected text read |
No |
| Anything uploaded |
No source, prompts, secrets or tool payloads leave your device |
| Network destinations |
Only the links you click (Resolver / TrustOps / Developer Gateway) open in your browser |
| Telemetry |
None |
| Retention |
None — no caller data is stored or persisted |
| Local storage |
Minimal extension state only |
| Workspace Trust |
Respected; scanning is gated by VS Code Workspace Trust |
See the bundled PRIVACY.md for the full notice.
Frequently asked questions
Is this extension free?
Yes. Every local check is free — you never need to sign in or pay to run one.
Does it upload my source code?
No. No source, prompts, secrets or tool payloads ever leave your device, and there is no telemetry.
Does it read my file contents?
It reads filenames and paths during a scan. It only reads the contents of a file you explicitly ask it to inspect (for example an ecz-*.json you choose to validate).
Does a missing proof reference mean something is unsafe?
No. “No public proof reference found yet” is neutral — it is not a verdict of “unsafe”. It only means resolver-verifiable public proof was not detected.
What does Resolver do?
Resolver is a read-only public proof lookup. The extension can open it so you can check public proof yourself; the extension never writes, activates or decides anything.
Do I need an ECZ-ID before using the extension?
No. You can run every local check without one. An ECZ-ID is only relevant if you later choose supported setup in TrustOps.
What happens when I continue supported setup?
The extension hands off to TrustOps with metadata only. It runs no checkout itself; TrustOps handles acquisition, setup and lifecycle.
Can this extension make a compliance or approval decision?
No. It surfaces posture and routes you to proof. Local policy decides sufficiency; it never certifies, approves or guarantees.
Does installing the Hub install the specialist extensions?
Yes. The Hub is an Extension Pack: installing it installs the sixteen ECZ-ID specialist extensions — the seven core checks (Agent Trust, MCP Trust, API Security, CI/CD Trust, Dependency Security, Compliance Risk, Vendor Risk) plus SBOM Readiness, DORA Readiness, Cloud Trust, Counterparty Trust, Robotics Trust, and the Humanoid, Drone, Robotaxi & Freight, and Cargo & Marine insurance-readiness specialists.
Can each specialist extension be managed independently?
Yes. Each specialist can be enabled, disabled or uninstalled on its own; the Hub does not lock them together.
Does the Hub duplicate the specialist checks?
No. The Hub routes you to the right specialist for what your workspace actually contains; it does not re-implement their result engines.
What it does not do
- No source / prompt / secret upload, and no telemetry.
- Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
- Makes no safety, approval, certification or compliance claim.
- Runs no checkout or payment — commercial actions happen only in TrustOps.
Install & first use
- In your editor's Extensions view, search for ECZ-ID (publisher EcoCitizenz) and install it.
- Open a project and trust the workspace.
- Run
ECZ-ID: Scan Workspace and review the grouped findings.
Free vs supported setup
- Free, local-first: a grouped workspace scan across the core trust areas, plain-English posture, and one-click routing to the right specialist — no sign-in and no purchase to run a check.
- Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for an organisation-wide trust posture — relevant when you need a resolver-verifiable result others can check, not just local review.
- You never need to buy anything to get local value; supported setup is a separate, optional step handled entirely in TrustOps.
Python / CLI
Prefer Python, CI or terminal automation?
python -m pip install ecz-id
ecz-id --help
The Python tools run locally and inspect, explain and route only — the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.
Machine-readable facts
| Field |
Value |
| Product |
ECZ-ID |
| Identity |
ecocitizenz.eczid |
| Publisher |
EcoCitizenz |
| License |
Free; see the bundled LICENSE.txt |
| Version |
0.1.3 |
| Page family |
functional-extension |
| Purpose |
Run the right ECZ-ID trust check for your workspace — agents, MCP, APIs, CI/CD, dependencies, compliance, vendors, SBOM, DORA, cloud, counterparty, robotics and insurance-readiness. |
| Applicable audiences |
Engineering and platform teams with several trust surfaces in one repository; Security reviewers and enterprise architects; Operators coordinating checks across teams; Anyone deciding which ECZ-ID check to run first |
| Applicable scenarios |
a repository mixes agents, APIs, pipelines, dependencies and vendor evidence; an evaluator asks where to start; you want one cockpit before drilling into a specialist |
| Primary command |
ECZ-ID: Scan Workspace |
| Inputs |
Workspace files by name and path; ecz-agent.json, ecz-mcp.json, mcp.json references |
| Outputs |
A grouped workspace scan across the core trust areas, plain-English posture, and one-click routing to the right specialist |
| Data handling |
Filenames and paths only; no source / prompt / secret upload; no telemetry; retention none |
| Network behaviour |
Only the links you open (Resolver / TrustOps / Developer Gateway); no background network call |
| Result states |
evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides |
| Limitations |
Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout |
| Canonical machine discovery |
https://machine.ecocitizenz.org/.well-known/ecz-machine.json |
| Public proof |
https://resolver.ecocitizenz.org |
| Documentation |
https://developers.ecocitizenz.com |
| Supported setup |
https://trustops.ecocitizenz.com/start |
| Re-check |
Re-run before reliance |
Need help choosing the right ECZ-ID route?
Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance
Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.
Links & support
ECZ-ID is independent trust infrastructure. Third-party names describe compatible ecosystems only and do not imply endorsement or affiliation. Local policy decides whether the evidence you review is sufficient.