The Registry · Ghost Swarm running now

Every dependency
is a decision.
Make it on evidence.

Somebody on your team is about to pip install an agent framework they found this morning. It has 40k stars. Nobody has read its code, and stars have never once caught a CVE. Name it below — the swarm already ran it.

1,812
Tools Indexed
55,108
Sandboxes Run
3
Live Threat Flags
99.1%
Signal Quality
Name a tool. Get a ruling.
Not a score out of 100 — a decision, in the context of who's deploying it. Finance carries different risk than a research notebook.
Risk tolerance
Querying the swarm ledger…
Trust Score
Active CVEs
Certificate
SBOM Packages
Evidence Bundle
Last Evaluated
Behavioral Drift
Live from the sandbox

What the machines found while you were reading this.

Every row is a real container that was built, booted, probed and torn down — memory sampled, egress watched, SBOM scanned. Nothing here is self-reported by a vendor.

ToolScoreCategory Reliability Memory Latency CVEs OWASPLast audit
Loading the registry…
Showing of most recently audited · full directory at /tools
Your stack, not just your tools

Tools that pass individually can still combine into a risky flow once deployed together. That's a different question than "is this tool safe" — and it needs a different check.

Run a stack audit →
Compliance packet

Turn a ruling into an audit artifact.

SOC 2, ISO 27001 and NIST AI RMF control mappings, OWASP LLM findings, and memory/latency telemetry — exported as one Ed25519-signed PDF your auditor can verify offline.

Generate a packet →
Pro tier · ~90s per packet · delivered to your Console

Put this in your CI, not in a browser tab.

The same ruling you just ran is one API call. Block the merge before the dependency lands, not after the incident review.

Get API access → Run a swarm node →