VerditNxtGen was built because the AI tooling market had a telemetry problem — teams were making production infrastructure decisions based on social proof. We built the missing evidence layer.
The open-source AI tool ecosystem exploded in 2024–2025. Every week, new agent frameworks, vector databases, and MCP servers would appear on GitHub trending — getting 3,000 stars in a day and being adopted by engineering teams without a single deployment test.
We started building internal tooling to measure what GitHub couldn't tell us: how much RAM does this thing actually use? Does it start reliably? Does it have prompt injection vulnerabilities that would expose our infrastructure?
That internal tooling is now VerditNxtGen. Ghost Swarm runs automated sandboxes against every indexed tool, every day. The results go into D1. The scores go to anyone who needs them. No hidden weights. No vendor money.
Scraper identifies new tools via GitHub trending, curated submission forms, and direct maintainer partnerships. Tools are added to D1 with raw GitHub telemetry before any sandbox run.
Ghost Swarm pulls each tool's Docker image and runs it in an isolated container. It captures peak RAM (Bloat Index), init latency, and exit code. Harness bugs — caused by our own infrastructure, not the tool — are identified and excluded from scoring.
Results are combined with 12 GitHub signals using category-specific weight profiles. The final Verdit Score (0–100) is published to the directory, API, and compliance reports.
VerditNxtGen is a venture within OneZero Network — an enterprise infrastructure conglomerate building the shared cryptographic and governance layer for enterprise data, agentic workflows, and resource orchestration.
The OZN engine provides VerditNxtGen's sandboxed execution environment (Ghost Swarm runs on Pillar 01), edge-native key management for API authentication (Pillar 02), and AI resource governance for Bloat Index tracking (Pillar 04). Security here is not a product feature — it's the substrate.
Explore the OZN Platform →We do not accept payment from tool vendors to influence scores or placement. A tool with 10 GitHub stars can outrank one with 30,000 if the telemetry supports it.
Every score component is documented. Every signal weight is published. You can reproduce any Verdit Score from first principles using our methodology page.
When our own infrastructure causes a test failure, we flag it as a harness bug and exclude it from scoring. A tool should not be penalised for our Docker registry outages.
Our compliance PDFs include the raw telemetry data, not just the conclusions.
Weekly score digest — movers, new tools, OWASP findings, and bus-factor warnings.