Tools, agents, and subagents — checked for reliability and safety across the SDK surface.
View Claude rules →Tools, agents, and project-wide configuration — checked for reliability and safety.
View OpenAI rules →Function tools and LlmAgents — checked for reliability and safety across all supported languages.
View ADK rules →MCP server tool registrations and config files — audited by a dedicated MCP rule pack.
View MCP rules →Install via Homebrew, Scoop, Docker, or a direct binary download. Works on macOS, Linux, and Windows — no runtime dependencies.
docs/installation →Run your first scan in two commands. Trustabl reads your repo, discovers every agent and tool, and produces a deterministic reliability report.
docs/quick-start →Gate agent code in CI, annotate pull requests with GitHub Code Scanning (SARIF), run pre-release audits, or scan third-party dependency repos.
docs/use-cases →A flat, deterministic pipeline: recon → inventory → policy selection → analysis → scoring. Identical inputs always produce identical output.
docs/how-it-works →Full SDK-by-language coverage matrix. Claude SDK, OpenAI Agents SDK, Google ADK, MCP tool registrations, and shell-invocation risk surface.
docs/coverage →Human-readable terminal output, structured JSON for pipelines, and SARIF 2.1.0 for GitHub Code Scanning annotations with stable fingerprints.
docs/output-formats →Every flag, command, and exit code. trustabl scan, trustabl rules pull, output control, strict mode, and more.
docs/cli-reference →Every check Trustabl runs, across all supported SDKs — each with the threat model behind it, risk score, confidence level, and link to its YAML source.
docs/rules →| ID | Scope | Policy | Severity | Risk |
|---|