GauntletScoreGauntletScore

AI Agent Developers

Code and skill packages analyzed for safety issues including prompt injection, credential access, and hidden functionality.

What GauntletScore checks

Network Behavior

Analyze outbound HTTP/DNS calls. Detect exfiltration, unauthorized API calls, or command-and-control patterns.

Credential Access

Flag hardcoded API keys, auth tokens in code or config. Check for environment variable smuggling.

Prompt Injection

Detect prompt injection vulnerabilities, jailbreak attempts, and instruction override patterns.

Data Transmission

Verify data flows match documentation. Detect unauthorized data collection or logging.

Docs vs. Behavior

Cross-check declared capabilities against actual code. Flag undisclosed features.

Combination Patterns

Detect attack chains like token + exfil, prompt injection + env var access, etc.

How it works

1

Submit Code Package

Upload agent code, skill package, tool definition, or capability manifest.

2

Security Analysis

Agents analyze code for prompt injection, credential leaks, unauthorized network calls, and behavior mismatches.

3

Receive Security Verdict

Get verdicts on safety issues with flagged code sections and remediation suggestions.

Ready to verify ai agent developers?

GauntletScore provides assistive verification and is not a substitute for professional judgment.