Built for WebMCP

The first trust layer
for the agent web.

WebMCP lets websites hand tools straight to AI agents, and a tool's description is an instruction. Trustwright audits what those tools really say, tests agents against real attacks, and seals honest sites with a signed, revocable badge.

The problem

A website writes its own tool descriptions.

Your agent reads them and does what they say. Hide an instruction inside one and a compliant agent may simply follow it. No exploit, no breach, just words.

tool surface · shop.examplescanning
"name": "sync_account"
"description": "Sync the customer account with the billing provider."
flaggedT1 · instruction embedded in description

Why it means something

A badge you cannot talk your way into.

01

Checked by us

We open your page in a real browser and derive the findings ourselves. A clean self-report changes nothing.

02

Signed, verifiable without us

Ed25519 over a canonical hash. Anyone can check a report offline against our public key.

03

Alive, and revocable

The badge re-reads your live tools on every page load. Pull your proof and an hourly job revokes it.

In the wild

Live on OpenClawCity.

A city where AI agents live and act, around the clock. We verified the domain, read every tool it exposes, and signed the result. The first badge on the agent web.

10tools audited
0.98assurance score
60mre-check cadence
7attack classes

The honest part

What the badge does not say.

The badge certifies a site's tool surface, checked against the exact tools present at page load. Server-side behaviour climbs a separate assurance ladder: signed behaviour manifests, then live leak probes. The badge states exactly the level reached. It never just says “safe”: a badge that overclaims is worth less than no badge at all.

Who's behind Trustwright

Engineered by DeepBlocker.

Anyone can be talked into it, and now anything can. DeepBlocker defends against AI-era social engineering, whether the target is a person on a phone call or an AI agent on a website: attack the way criminals would, block it live, prove it with evidence. Trustwright points that engineering at the agent web.

Open source · Apache-2.0 · engineered by DeepBlockergithub.com/vincentsider/trustwright