Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>ECZ-ID Agent TrustNew to Visual Studio Code? Get it now.
ECZ-ID Agent Trust

ECZ-ID Agent Trust

EcoCitizenz

|
164 installs
| (0) | Free
Know what your AI agents can reach and how their authority changes before they act. Local-first discovery of declared tools, credential-shaped environment key names and workspace MCP relationships. Community is free forever. No account, no telemetry.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

ECZ-ID Agent Trust

Know what your AI agents can reach. See how their authority changes before they act.

Local-first agent visibility and authority intelligence for Visual Studio Code.

An agent can only act on what it can reach. That reach is assembled from scattered places — a manifest here, a tool spec there, an MCP server list, a handful of environment keys, a framework's own conventions — and it grows quietly. A tool is added, a permission widens, a new MCP relationship appears, and nothing announces it.

Agent Trust makes that reach legible. It discovers the agent surfaces in your workspace, inventories what each one declares, maps the authority that follows from it, and tells you what changed since you last looked.

It runs entirely on your machine. No source, prompts, tool arguments, tool results or secret values are uploaded. No account. No telemetry.

Editions

Edition Price What it is for
Agent Trust Community £0 — free forever Discover agent surfaces, see declared tools and reach, and track what changed.
Agent Trust Pro £12.99/month or £119/year Map full authority, expose consequential action chains, and keep the history.
Developer Trust Pro £19.99/month or £199/year Agent Trust Pro and MCP Trust Pro on one licence.

Protect both sides of the agent ↔ MCP connection. One licence.

Explore Agent Trust Pro →
Explore Developer Trust Pro →
Already purchased? Activate Pro →

The Marketplace download is free because Community is genuinely free forever. Pro is an optional entitlement that unlocks additional capability inside this same extension.

What you get the moment you install it, for £0

  • Find the agents you actually have. Detects agent manifests, framework signals, MCP tool configuration, tool/action specs and webhooks.
  • See what each one declares. Agent X-Ray inventories the agent surfaces you scan: declared tool names, environment variable names (never values), framework labels and a local posture fingerprint per surface.
  • See the MCP servers in the picture. Workspace MCP relationships are surfaced alongside the agents that reference them.
  • Know what moved. Each scan records a local baseline, and the next scan says exactly what changed — tools, environment key names, frameworks, MCP relationships.
  • Read plain English, not a verdict. Posture is described, never scored; there is no "acceptable" or "unacceptable" judgement.
  • Check public proof. One click to a read-only Resolver lookup, and local ecz-agent.json validation or scaffolding when you ask for it.

No sign-in. No trial. No expiry.

Coverage: OBSERVED locally / UNMANAGED — agent configuration is inspected on this machine. This extension does not mediate or enforce runtime agent execution, and never claims to.

Agent Trust Community — £0, free forever

Community is not a trial and not a teaser. It is the whole discovery and inspection product:

  • agent-surface discovery across manifests, frameworks, tool specs and webhooks
  • Agent X-Ray inventory of declared tools and capabilities
  • credential-shaped environment key-name visibility
  • workspace MCP relationships
  • local change detection against a baseline
  • ecz-agent.json validation and scaffolding, only when you ask
  • Resolver public-proof lookup and supported-setup routes
  • no paid account, no sign-in, no telemetry

If all you want is to see what your agents declare and what changed, Community does that permanently and for nothing.

Agent Trust Pro — £12.99/month or £119/year

Community tells you what each agent declares. Pro tells you what that adds up to — the reach that emerges when tools, credentials, MCP targets and external destinations are considered together, and how it moves over time. Everything still computes locally, from discovered evidence.

Understand an agent's total reach, not just its tool list

Authority Graph builds a local graph of agents, tools, MCP targets, APIs, credential key names, declared permissions and capability signals. Every node and edge is derived from discovered evidence and shows that evidence. No trust score is computed, and credential nodes carry key names only.

See the combinations that deserve a human look

Dangerous action chains surface deterministic indicators — credential access → external send, credential access → destructive capability, filesystem access → network send, package mutation → deployment. Each shows its nodes, edges, reason, source evidence and a remediation suggestion. They are indicators for review, never a declaration that an agent is unsafe or malicious.

See how an agent's authority evolved

Authority Epochs retain local snapshots and compare any two: authority added or removed, permissions widened or narrowed, new MCP references, new API origins, new credential-key exposure, new external destinations, and newly appearing production or destructive capability.

Read the agent ↔ MCP relationship from both ends

Reciprocal Agent ↔ MCP view matches an agent's declared MCP servers against this workspace's MCP inventory, with truthful coverage. "ENFORCED VIA LOCAL TRUST GATE" is shown only when ECZ-ID MCP Trust holds a live gate session; Resolver public proof stays separate from local policy.

Fix what you find, reversibly

Remediation produces reviewable configuration patches: preview, diff, timestamped backup, atomic apply and rollback.

Explore Agent Trust Pro → · Activate Pro →

Community keeps working if a Pro entitlement is absent or expires. Only Pro features deactivate, and your locally retained history stays.

Developer Trust Pro — £19.99/month or £199/year

An agent is one side of the connection. The MCP servers it calls are the other. Agent Trust tells you what an agent can reach; ECZ-ID MCP Trust tells you what those servers expose and what changed about them. Reviewing one without the other leaves the interesting half unexamined.

Developer Trust Pro unlocks both Agent Trust Pro and MCP Trust Pro under a single entitlement, for less than buying the two separately.

Protect both sides of the agent ↔ MCP connection. One licence.

Explore Developer Trust Pro →

Operate an agent or an MCP server?

Give it an ECZ-ID Passport.

Everything above inspects agents from the outside — the position you are in when you evaluate someone else's agent. If you operate an agent or an MCP server, you are on the other side of that question, and the people evaluating you want something they can check without asking you.

An ECZ-ID Passport establishes a reusable ECZ-ID identity with a public presence on the ECZ-ID Resolver, so a reviewer can verify public proof themselves.

  • Free, fast self-service
  • A reusable machine-readable identity, not a one-off badge
  • Public, read-only Resolver presence others can check

Operate an agent? Give it a free ECZ-ID Agent Passport →

Operate an MCP server? Give it a free ECZ-ID MCP Passport →

Both Passports are available whichever extension you started from — most teams that run agents also run MCP servers, and the same ECZ-ID identity layer covers both. See also ECZ-ID MCP Trust for local MCP visibility.

Passport issuance is an ECZ-ID platform service, not a function of this extension. The extension inspects and routes; it never issues proof itself.

Who this is for

If you are… The problem you have What Agent Trust gives you
An AI-agent builder Your agent's reach is spread across a manifest, a tool spec, an env block and an MCP list, and no single view shows it. Agent X-Ray for what is declared, and the Authority Graph for what it amounts to.
An MCP or agent developer Agents and servers evolve independently and drift apart silently. Change detection against a baseline, plus the reciprocal Agent ↔ MCP view.
An AppSec or security engineer You are asked to review agents with no artefact to review, and tooling that would read prompts or secrets is not acceptable. A privacy-preserving inventory and exportable local evidence — prompts, tool arguments, tool results and secret values are never read into output.
A platform engineer Teams add agents faster than anyone can track what they can touch. Workspace-wide discovery and reviewable remediation.
An enterprise architect You must state a defensible position on agent authority. Explicit OBSERVED / UNMANAGED semantics and evidence-backed graph output that never overstates what was established.
Integrating third-party agents You are granting reach to something you did not write. Declared-capability visibility and dangerous action-chain indicators before you grant access.

Most relevant when you are wiring an agent or MCP tool, before you grant an agent tool access, when an evaluator asks for agent provenance, or when you are reviewing a third-party agent.

What you can do in under a minute

  1. Open or scan the workspace - run ECZ-ID Agent Trust: Scan Workspace.
  2. Review findings in plain English - grouped, with neutral posture.
  3. Open Resolver guidance or continue supported setup where relevant.

What it looks for

  • Agent manifests (agent.yaml, agent.json) and tool / action specs.
  • Agent frameworks (LangChain/LangGraph, CrewAI, AutoGen, Semantic Kernel, LlamaIndex, OpenAI, Anthropic).
  • MCP tool configuration and webhooks an agent may call.
  • Whether an ecz-agent.json / .well-known/ecz-agent.json resolver reference is present.

Example result

ECZ-ID Agent Trust  -  2 agent surfaces
- agent.yaml ........... no ecz-agent.json reference found yet
- mcp tool config ...... resolver reference present
Posture: neutral - local policy decides, re-check before reliance

What results mean

Results describe public-proof posture, never a safety, approval, certification or compliance verdict:

resolvable | partial public proof | no public proof reference found yet | review recommended | re-check before reliance | your local policy decides.

There is no "pass/fail". Local policy decides what is sufficient, and you should re-check before reliance.

Recommended next steps

  • Inspect the finding - plain-English detail, no verdict.
  • Copy verification guidance - a claim-free snippet you can share.
  • Open Resolver - read-only public proof lookup.
  • Continue supported setup - hand off to TrustOps (metadata only).
  • Open documentation - Developer Gateway.
  • Re-check later - re-run before you rely on a result.

Privacy & permissions

Question Answer
Files read Filenames and paths during a scan; the contents of files the scan classifies as agent or MCP JSON configuration are then locally inspected (strict JSON, 256 KiB limit) to build the Agent X-Ray
What is extracted from contents Names, enums and counts only: declared tool names, environment variable names, framework labels, and a local posture fingerprint. Environment variable values are never read into results
YAML / other formats Observed by filename only and honestly labelled as not content-inspected
Selected text read No
Anything uploaded No source, prompts, secrets or tool payloads leave your device
Network destinations Only the links you click (Resolver / TrustOps / Developer Gateway) open in your browser, each behind a disclosure
Privacy mode Enforced: local-only (default) opens the public check with no detected metadata; metadata-only encodes filename/classification metadata only, after a disclosure
Telemetry None
Retention One local baseline snapshot per workspace (names, enums, counts, fingerprints only), replaced on each scan, stored in VS Code workspace state
Workspace Trust Enforced; in Restricted Mode no workspace file is scanned or read

See the bundled PRIVACY.md for the full notice.

Frequently asked questions

Is this extension free?

Yes. Agent Trust Community is free forever - you never need to sign in or pay to run a local check, and it does not expire. Agent Trust Pro is an optional paid entitlement (£12.99/month or £119/year) that unlocks additional capability in this same extension, and Developer Trust Pro (£19.99/month or £199/year) unlocks Agent Trust Pro and MCP Trust Pro together.

What is the difference between Agent Trust Pro and Developer Trust Pro?

Agent Trust Pro covers this product only. Developer Trust Pro covers both sides of the agent-to-MCP connection - Agent Trust Pro plus MCP Trust Pro - on one licence, for less than the two bought separately.

What is an ECZ-ID Agent Passport, and do I need one to use this?

You do not need one. A Passport is for the opposite position: it is relevant when you operate an agent and want a reusable ECZ-ID identity with public Resolver presence that reviewers can check for themselves. It is a free, self-service ECZ-ID platform service, not a feature of this extension.

Does it upload my source code?

No. No source, prompts, secrets or tool payloads ever leave your device, and there is no telemetry.

Does it read my file contents?

A scan you run reads filenames and paths, then locally inspects the contents of files it classified as agent or MCP JSON configuration (strict JSON only, 256 KiB limit) to build the Agent X-Ray. Only names, enums, counts and fingerprints are kept - environment variable values are never read into results, and nothing is uploaded. YAML and other formats are observed by filename only and labelled as such.

Does a missing proof reference mean something is unsafe?

No. "No public proof reference found yet" is neutral - it is not a verdict of "unsafe". It only means resolver-verifiable public proof was not detected.

What does Resolver do?

Resolver is a read-only public proof lookup. The extension can open it so you can check public proof yourself; the extension never writes, activates or decides anything.

Do I need an ECZ-ID before using the extension?

No. You can run every local check without one. An ECZ-ID is only relevant if you later choose supported setup in TrustOps.

What happens when I continue supported setup?

The extension hands off to TrustOps with metadata only. It runs no checkout itself; TrustOps handles acquisition, setup and lifecycle.

Can this extension make a compliance or approval decision?

No. It surfaces posture and routes you to proof. Local policy decides sufficiency; it never certifies, approves or guarantees.

Which agent frameworks can it detect?

Common agent manifests and frameworks - LangChain/LangGraph, CrewAI, AutoGen, Semantic Kernel, LlamaIndex - plus tool/action specs and MCP tool configurations.

What does the manifest scaffold command change?

Only ecz-agent.json, and only when you invoke it. It reads and writes that single local file; nothing else is touched.

Does it run or call my agents?

No. It inspects local files only. It never executes an agent, tool or webhook.

Is the Authority Graph inferred or invented (Pro)?

Neither - every node and edge comes from deterministic discovered evidence and carries its source. An agent->MCP edge is drawn only when the agent's declared server name also appears in this workspace's MCP inventory. No trust score is computed.

Are dangerous action chains saying my agent is unsafe (Pro)?

No. They are risk indicators derived from declared configuration, each with its nodes, edges, reason and evidence, so you can judge for yourself. They never declare an agent unsafe or malicious.

When does the reciprocal view show ENFORCED (Pro)?

Agent Trust never mediates MCP traffic, so it shows coverage as OBSERVED. "ENFORCED VIA LOCAL TRUST GATE" for an MCP target is shown by ECZ-ID MCP Trust while it holds a live gate session for that exact server. Resolver public proof is a separate concept.

What happens to Pro features when my entitlement expires?

Pro features deactivate on the next verification; Community continues in full and your locally retained history is kept. Entitlements are verified locally with asymmetric (ES256) cryptography; the entitlement token is never displayed or transmitted by this extension.

What it does not do

  • No source / prompt / secret upload, and no telemetry.
  • Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
  • Makes no safety, approval, certification or compliance claim. Does not imply that any agent is acceptable or unacceptable. The optional scaffold/validate command reads only ecz-agent.json, and only when you invoke it.
  • Runs no checkout or payment - commercial actions happen only in TrustOps.

Install & first use

  1. In your editor's Extensions view, search for ECZ-ID Agent Trust (publisher EcoCitizenz) and install it.
  2. Open a project and trust the workspace.
  3. Run ECZ-ID Agent Trust: Scan Workspace and review the grouped findings.

Free vs Pro vs supported setup

  • Community (£0, free forever, local-first): detected agent surfaces with neutral posture, Agent X-Ray, change detection, missing-public-proof findings, and Resolver / supported-setup routes - no sign-in and no purchase to run a check.
  • Agent Trust Pro (£12.99/month or £119/year, still local): Authority Graph with evidence on every edge, Authority Epochs, dangerous action-chain indicators, the reciprocal Agent ↔ MCP view, and reviewable remediation. Activate with a Developer Trust entitlement; Developer Trust Pro (£19.99/month or £199/year) unlocks MCP Trust Pro alongside it.
  • Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for agent identity and public proof - relevant when you need a resolver-verifiable result others can check, not just local review.
  • You never need to buy anything to get local value; Pro and supported setup are separate, optional steps.

Python / CLI

Prefer Python, CI or terminal automation?

python -m pip install ecz-id-agents
ecz-id-agents --help
  • Open the matching Python package: https://pypi.org/project/ecz-id-agents/
  • Explore all 10 ECZ-ID Python tools: https://developers.ecocitizenz.com/python

The Python tools run locally and inspect, explain and route only - the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.

Machine-readable facts

Field Value
Product ECZ-ID Agent Trust
Identity ecocitizenz.eczid-ai-agents
Publisher EcoCitizenz
License Community free; Pro requires a Developer Trust entitlement; see the bundled LICENSE.txt
Version 0.4.4
Page family functional-extension
Editions Community (free, no sign-in) / Agent Trust Pro / Developer Trust Pro bundle
Purpose Resolve the agent before you allow it to act; with Pro, map an agent's authority from evidence and surface dangerous action chains.
Applicable audiences AI-agent and MCP tool builders; Platform and AppSec teams integrating agents; Enterprise architects reviewing agent posture; Reviewers and architects evaluating third-party agents
Applicable scenarios you are wiring an agent or MCP tool; before granting an agent tool access; an evaluator asks for agent provenance; you are reviewing a third-party agent
Primary command ECZ-ID Agent Trust: Scan Workspace
Inputs Agent manifests (agent.yaml / agent.json), framework configs, MCP tool configs (including .vscode/mcp.json, .mcp.json, .mcp/), webhooks, ecz-agent.json
Outputs Detected agent surfaces with neutral posture, a local Agent X-Ray inventory (tool names, environment key names, fingerprints), change-since-previous-scan findings, and Resolver / supported-setup routes
Data handling Filenames/paths plus local JSON content inspection of classified agent/MCP configs; names, enums, counts and fingerprints only; environment variable values never read into results; no source / prompt / secret upload; no telemetry; one replaceable local baseline per workspace
Coverage OBSERVED locally / UNMANAGED - runtime agent execution is not mediated or enforced
Network behaviour Community and Pro alike: only the links you open (Resolver / TrustOps / Developer Gateway); no background network call, and no mediation - Agent Trust never sits in an agent's or server's call path
Result states evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides
Limitations Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout
Canonical machine discovery https://machine.ecocitizenz.org/.well-known/ecz-machine.json
Public proof https://resolver.ecocitizenz.org
Documentation https://developers.ecocitizenz.com
Supported setup https://trustops.ecocitizenz.com/start
Re-check Re-run before reliance

Need help choosing the right ECZ-ID route?

Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance

Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.

The ECZ-ID estate

Agent Trust is one surface of ECZ-ID, an infrastructure layer for machine trust — identity, public proof and verifiable posture for the systems that now call each other without a human in the loop.

ECZ-ID MCP — identity and public proof for MCP servers https://mcp.ecocitizenz.com/
Agent Trust — this product https://developers.ecocitizenz.com/agent-trust/
MCP Trust — the other side of the connection https://developers.ecocitizenz.com/mcp-trust/
Developer Trust — both, one licence https://developers.ecocitizenz.com/developer-trust/
ECZ-ID Resolver — read-only public proof lookup https://resolver.ecocitizenz.org/
EcoCitizenz Ltd on GitHub https://github.com/EcoCitizenz-Ltd

Links & support

  • Resolver (read-only proof): https://resolver.ecocitizenz.org
  • TrustOps (supported setup): https://trustops.ecocitizenz.com/start
  • Activate Pro: https://trustops.ecocitizenz.com/developer-trust/activate
  • Developer Gateway (docs & support): https://developers.ecocitizenz.com
  • EcoCitizenz Ltd on GitHub: https://github.com/EcoCitizenz-Ltd
  • Privacy: see the bundled PRIVACY.md file
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft