Acquire AgentScore
AgentScore is a working, public security scanner for MCP packages on npm. It is for sale as an asset deal. This page tells you exactly what you would be buying and is honest about what you would not be.
The reason it is for sale is plain. It was built and run by one person as proof that MCP supply-chain risk could be scanned, scored, and disclosed continuously. It does that. It was never turned into a revenue business, and the standalone-scanner market has consolidated around larger players. The assets below are real, the scanning pipeline has run every day without a gap since March 31, 2026, and the right home for this is a team already building in MCP or supply-chain security.
What is included
Live external machine consumers (found with zero marketing)
Since June 2026, at least five distinct external agents have found the verdict API and wired it into their own loops, unprompted, during a period with no marketing of any kind. One has used it across 28 separate days and is still active, running a full verdict, scan, exposure, and monitor pipeline against a monitored stack of packages; the others range from multi-day evaluations to short trials, and several are now dormant. Combined, roughly 1,500 API calls checking real MCP packages, with more than one consumer calling in the last 24 hours. This is documented organic adoption of the primitive, not revenue and not a named customer base, and it is the hardest-to-fake asset here: telemetry, not claims. What they check is itself a finding: 71% of agent risk-checks land on the official MCP servers.
The scanner engine and ruleset
A continuous scanner that pulls npm tarballs, walks their source for risk patterns (command injection, unsafe eval, hardcoded secrets, prompt-injection markers), classifies MCP tool capabilities, and scores each package. It carries a public precision-correction history: a dated changelog of its own false positives and false negatives and how each was fixed. That discipline is rare and is itself part of the asset.
A continuous scan time-series dataset
40,489 scans across 1,626 monitored MCP packages and more than 10,000 distinct package-versions, captured daily with no gap since March 31, 2026. Score, findings, dependency snapshot, and capability analysis per version over time. Current state can be re-derived by anyone with a scanner; the longitudinal history, the removed-version coverage, and the dated first-observation timestamps cannot be regenerated after the fact.
A public advisory archive with real provenance
80 published security advisories with timestamped first-observation data, an RSS feed, and auto-filed GitHub issues. The provenance is the value: Redis pinned every MCP dependency in RedisInsight after a scan, Grafana pinned a package in k6-studio, and Agions and HomenShum shipped fixes. These are closed-completed issues in third-party repositories, not claims.
An official MCP registry listing and four npm packages
A listing in the official Model Context Protocol registry (io.github.Thezenmonster/agentscore, marked latest), plus four published npm packages including the MCP server client that lets any agent query the scanner. CI auto-publishes on tag push via OIDC trusted publishing.
The domain, the site, and the indexed surface
agentscores.xyz with around 960 indexed URLs: package reports, repo dossiers, the advisory feed, research, and case studies. A full Next.js application, the monitoring crons, the policy-gate API and GitHub Action, and the supporting infrastructure.
Likely buyers
Teams already extending into MCP or software supply-chain security, MCP registries and directories that want a per-server risk signal, and security-research groups that would value the longitudinal dataset and disclosure archive. The founder is not available for employment; this is structured as a clean asset purchase with a short paid transition if useful.
Make an approach
Tell us who you are and what you are building. Inquiries are logged and forwarded straight to the owner; we will share scan samples, dataset extracts, and the full asset inventory under a short conversation. Operated by Janus Compliance Limited (UK company number 16583861).