Static pre-deployment boundary
AgentReady inspects contract structure, descriptions, input schemas, risk indicators and policy outcomes before an agent uses a tool. It does not monitor live sessions or enforce production authorization.
Security model
The Community scanner performs static analysis of OpenAPI documents and MCP tool definitions. It does not execute submitted APIs, MCP tools, LLM calls or customer systems.
AgentReady inspects contract structure, descriptions, input schemas, risk indicators and policy outcomes before an agent uses a tool. It does not monitor live sessions or enforce production authorization.
Community use does not require a TimeProofs account, a hosted scanner, API upload, backend database, billing system or secret.
AgentReady can flag structural risks in OpenAPI and MCP contracts. It cannot prove that live code, authorization policy, runtime prompts, logs, secrets, production data or dynamic tool construction are safe.
The npm package and GitHub Action are public distribution paths. Users should pin immutable versions or full commit SHAs where appropriate and review generated reports before enforcing gates.
TimeProofs AgentReady does not guarantee that an AI agent will never fail. It identifies structural risks that may cause AI agents to misuse APIs, tools or MCP servers.
AgentReady is static pre-deployment analysis; it is not a runtime firewall, IAM system, hosted scanner, audit or guaranteed-safety system. AgentReady is a product and candidate open standard for static pre-deployment analysis. It is not a runtime firewall, independent certification, official standards-body standard or guaranteed-safety system.