Skip to content

Improve marketing material#2

Merged
brian93512 merged 16 commits intoAgentSafe-AI:mainfrom
alexyorke:main
Apr 5, 2026
Merged

Improve marketing material#2
brian93512 merged 16 commits intoAgentSafe-AI:mainfrom
alexyorke:main

Conversation

@alexyorke
Copy link
Copy Markdown
Contributor

I focused this more on marketing it like a startup, however, if you're looking for maybe a more neutral revision I can do that too. The "security alert" thing at the top of the readme is a bit alarming, I read that first before reading what the tool was and I thought the security alert was the security of tooltrust-scanner itself.

I have not verified all facts, figures, etc. in this revised readme comprehensively, so, it's more of a direction.

Revert "Initial readme improvement"

This reverts commit 262dd5a7b5d29419e79308d71bd377d0ab7512ba.

Improve marketing materials
@brian93512
Copy link
Copy Markdown
Member

thanks, the scanning rules currently should be 13 rules, right?

Combine upstream Glama badges, live UI, and usage links with fork marketing (207-server stats, install table). Clarify AS-008 as findings on dependencies, not ToolTrust itself. Document 12 active rules vs AS-012 planned for reviewer question. Take npm version 1.0.9 from upstream.

Made-with: Cursor
Revert synthesized merge README to pre-merge fork content from a6854e3.

Made-with: Cursor
os.UserHomeDir uses USERPROFILE on Windows; only setting HOME left real ~/.claude.json visible. Redirect HOME, USERPROFILE, and HOMEDRIVE/HOMEPATH to the temp dir during tests.

Made-with: Cursor
Fork PRs (e.g. PR AgentSafe-AI#2) fail the Test job when codecov-action uses use_oidc: true because ACTIONS_ID_TOKEN_REQUEST_URL is not set in that context. Gate the upload to same-repo PRs and pushes only. Include README small-additions (protocol role, transport note, data access column, deployment link).

Made-with: Cursor
- scripts/verify-ci-parity.sh mirrors Ubuntu test, coverage, build, self-scan - .gitattributes forces LF for shell scripts - CONTRIBUTING: fork workflow approval + Docker commands to reproduce CI

Made-with: Cursor
Go and shell sources are already LF in the tree; local Docker parity matches CI (lint, tests, coverage).

Made-with: Cursor
@alexyorke
Copy link
Copy Markdown
Contributor Author

The rule AS-012 exists but apparently isn't hooked up anywhere in the code (inaccessible), however, I can change it to 13 rules if you want to

@alexyorke
Copy link
Copy Markdown
Contributor Author

The CI has an error "Error: Codecov: Failed to get OIDC token with url: https://codecov.io./ Error message: Unable to get ACTIONS_ID_TOKEN_REQUEST_URL env variable" it appears that I might need you to run it again

…md (no synthesized readme)

Made-with: Cursor
@brian93512
Copy link
Copy Markdown
Member

The Codecov OIDC issue has already been fixed on main, but this PR branch is still behind main and currently has merge conflicts. Because of that, GitHub is skipping or blocking some required checks. Please update this branch with the latest upstream main, resolve the conflicts, and push again so CI can rerun with the fixed workflow.

README.md Outdated
| Servers with a clean Grade A | 22 (10%) |
| Servers with arbitrary code execution | 16 |

**Only 10% of MCP servers get a clean bill of health.** [Read the full analysis →](docs/blog-post-draft.md)
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the link does not exist

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's the new link I can use?

- Hero and copy: emphasize scanner value; live directory UI before GIF
- Frame 207-server table as labeled research cohort; point to tooltrust.dev
- 16 rules + AS-014–AS-017 table; AS-012 + ToolTrust Directory note
- Remove Homebrew install (unsupported per review)
- Drop blog-post-draft link; use stable directory URLs
- org-profile: broader scope, skills roadmap, aggregate stats via directory
- README-mcpso: align messaging and rule count with main README

Made-with: Cursor
Copy link
Copy Markdown
Member

@brian93512 brian93512 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@brian93512 brian93512 merged commit c8e22db into AgentSafe-AI:main Apr 5, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants