ECZ-ID Agent TrustKnow what your AI agents can reach. See how their authority changes before they act.Local-first agent visibility and authority intelligence for Visual Studio Code. An agent can only act on what it can reach. That reach is assembled from scattered places — a manifest here, a tool spec there, an MCP server list, a handful of environment keys, a framework's own conventions — and it grows quietly. A tool is added, a permission widens, a new MCP relationship appears, and nothing announces it. Agent Trust makes that reach legible. It discovers the agent surfaces in your workspace, inventories what each one declares, maps the authority that follows from it, and tells you what changed since you last looked. It runs entirely on your machine. No source, prompts, tool arguments, tool results or secret values are uploaded. No account. No telemetry. Editions
Protect both sides of the agent ↔ MCP connection. One licence. Explore Agent Trust Pro →
What you get the moment you install it, for £0
No sign-in. No trial. No expiry. Coverage: OBSERVED locally / UNMANAGED — agent configuration is inspected on this machine. This extension does not mediate or enforce runtime agent execution, and never claims to. Agent Trust Community — £0, free foreverCommunity is not a trial and not a teaser. It is the whole discovery and inspection product:
If all you want is to see what your agents declare and what changed, Community does that permanently and for nothing. Agent Trust Pro — £12.99/month or £119/yearCommunity tells you what each agent declares. Pro tells you what that adds up to — the reach that emerges when tools, credentials, MCP targets and external destinations are considered together, and how it moves over time. Everything still computes locally, from discovered evidence. Understand an agent's total reach, not just its tool listAuthority Graph builds a local graph of agents, tools, MCP targets, APIs, credential key names, declared permissions and capability signals. Every node and edge is derived from discovered evidence and shows that evidence. No trust score is computed, and credential nodes carry key names only. See the combinations that deserve a human lookDangerous action chains surface deterministic indicators — credential access → external send, credential access → destructive capability, filesystem access → network send, package mutation → deployment. Each shows its nodes, edges, reason, source evidence and a remediation suggestion. They are indicators for review, never a declaration that an agent is unsafe or malicious. See how an agent's authority evolvedAuthority Epochs retain local snapshots and compare any two: authority added or removed, permissions widened or narrowed, new MCP references, new API origins, new credential-key exposure, new external destinations, and newly appearing production or destructive capability. Read the agent ↔ MCP relationship from both endsReciprocal Agent ↔ MCP view matches an agent's declared MCP servers against this workspace's MCP inventory, with truthful coverage. "ENFORCED VIA LOCAL TRUST GATE" is shown only when ECZ-ID MCP Trust holds a live gate session; Resolver public proof stays separate from local policy. Fix what you find, reversiblyRemediation produces reviewable configuration patches: preview, diff, timestamped backup, atomic apply and rollback. Explore Agent Trust Pro → · Activate Pro → Community keeps working if a Pro entitlement is absent or expires. Only Pro features deactivate, and your locally retained history stays. Developer Trust Pro — £19.99/month or £199/yearAn agent is one side of the connection. The MCP servers it calls are the other. Agent Trust tells you what an agent can reach; ECZ-ID MCP Trust tells you what those servers expose and what changed about them. Reviewing one without the other leaves the interesting half unexamined. Developer Trust Pro unlocks both Agent Trust Pro and MCP Trust Pro under a single entitlement, for less than buying the two separately. Protect both sides of the agent ↔ MCP connection. One licence. Operate an agent or an MCP server?Give it an ECZ-ID Passport.Everything above inspects agents from the outside — the position you are in when you evaluate someone else's agent. If you operate an agent or an MCP server, you are on the other side of that question, and the people evaluating you want something they can check without asking you. An ECZ-ID Passport establishes a reusable ECZ-ID identity with a public presence on the ECZ-ID Resolver, so a reviewer can verify public proof themselves.
Operate an agent? Give it a free ECZ-ID Agent Passport → Operate an MCP server? Give it a free ECZ-ID MCP Passport → Both Passports are available whichever extension you started from — most teams that run agents also run MCP servers, and the same ECZ-ID identity layer covers both. See also ECZ-ID MCP Trust for local MCP visibility. Passport issuance is an ECZ-ID platform service, not a function of this extension. The extension inspects and routes; it never issues proof itself. Who this is for
Most relevant when you are wiring an agent or MCP tool, before you grant an agent tool access, when an evaluator asks for agent provenance, or when you are reviewing a third-party agent. What you can do in under a minute
What it looks for
Example result
What results meanResults describe public-proof posture, never a safety, approval, certification or compliance verdict: resolvable | partial public proof | no public proof reference found yet | review recommended | re-check before reliance | your local policy decides. There is no "pass/fail". Local policy decides what is sufficient, and you should re-check before reliance. Recommended next steps
Privacy & permissions
See the bundled PRIVACY.md for the full notice. Frequently asked questionsIs this extension free? Yes. Agent Trust Community is free forever - you never need to sign in or pay to run a local check, and it does not expire. Agent Trust Pro is an optional paid entitlement (£12.99/month or £119/year) that unlocks additional capability in this same extension, and Developer Trust Pro (£19.99/month or £199/year) unlocks Agent Trust Pro and MCP Trust Pro together. What is the difference between Agent Trust Pro and Developer Trust Pro? Agent Trust Pro covers this product only. Developer Trust Pro covers both sides of the agent-to-MCP connection - Agent Trust Pro plus MCP Trust Pro - on one licence, for less than the two bought separately. What is an ECZ-ID Agent Passport, and do I need one to use this? You do not need one. A Passport is for the opposite position: it is relevant when you operate an agent and want a reusable ECZ-ID identity with public Resolver presence that reviewers can check for themselves. It is a free, self-service ECZ-ID platform service, not a feature of this extension. Does it upload my source code? No. No source, prompts, secrets or tool payloads ever leave your device, and there is no telemetry. Does it read my file contents? A scan you run reads filenames and paths, then locally inspects the contents of files it classified as agent or MCP JSON configuration (strict JSON only, 256 KiB limit) to build the Agent X-Ray. Only names, enums, counts and fingerprints are kept - environment variable values are never read into results, and nothing is uploaded. YAML and other formats are observed by filename only and labelled as such. Does a missing proof reference mean something is unsafe? No. "No public proof reference found yet" is neutral - it is not a verdict of "unsafe". It only means resolver-verifiable public proof was not detected. What does Resolver do? Resolver is a read-only public proof lookup. The extension can open it so you can check public proof yourself; the extension never writes, activates or decides anything. Do I need an ECZ-ID before using the extension? No. You can run every local check without one. An ECZ-ID is only relevant if you later choose supported setup in TrustOps. What happens when I continue supported setup? The extension hands off to TrustOps with metadata only. It runs no checkout itself; TrustOps handles acquisition, setup and lifecycle. Can this extension make a compliance or approval decision? No. It surfaces posture and routes you to proof. Local policy decides sufficiency; it never certifies, approves or guarantees. Which agent frameworks can it detect? Common agent manifests and frameworks - LangChain/LangGraph, CrewAI, AutoGen, Semantic Kernel, LlamaIndex - plus tool/action specs and MCP tool configurations. What does the manifest scaffold command change? Only Does it run or call my agents? No. It inspects local files only. It never executes an agent, tool or webhook. Is the Authority Graph inferred or invented (Pro)? Neither - every node and edge comes from deterministic discovered evidence and carries its source. An agent->MCP edge is drawn only when the agent's declared server name also appears in this workspace's MCP inventory. No trust score is computed. Are dangerous action chains saying my agent is unsafe (Pro)? No. They are risk indicators derived from declared configuration, each with its nodes, edges, reason and evidence, so you can judge for yourself. They never declare an agent unsafe or malicious. When does the reciprocal view show ENFORCED (Pro)? Agent Trust never mediates MCP traffic, so it shows coverage as OBSERVED. "ENFORCED VIA LOCAL TRUST GATE" for an MCP target is shown by ECZ-ID MCP Trust while it holds a live gate session for that exact server. Resolver public proof is a separate concept. What happens to Pro features when my entitlement expires? Pro features deactivate on the next verification; Community continues in full and your locally retained history is kept. Entitlements are verified locally with asymmetric (ES256) cryptography; the entitlement token is never displayed or transmitted by this extension. What it does not do
Install & first use
Free vs Pro vs supported setup
Python / CLIPrefer Python, CI or terminal automation?
The Python tools run locally and inspect, explain and route only - the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof. Machine-readable facts
Need help choosing the right ECZ-ID route?Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance. The ECZ-ID estateAgent Trust is one surface of ECZ-ID, an infrastructure layer for machine trust — identity, public proof and verifiable posture for the systems that now call each other without a human in the loop.
Links & support
|