A2A agent that audits another deployed agent's source pre-deploy. Reads the target Gitea repo via a short-lived read-only token minted through ctx.mint_gitea_token(), runs an inner DeepAgents graph backed by GiteaBackend, and emits a typed ReviewReport. Skill bundles: - security-anti-patterns (credentials, eval, sandbox bypass, egress) - a2apack-best-practices (class shape, decorators, types, timeouts) - grant-scope-evaluation (declared vs actual workspace scope) Tools: - sandbox_a2a_card : round-trips the project through microsandbox - sandbox_ruff_check: objective static checks - submit_review_report: typed final report 7 smoke tests pass; agent card loads cleanly via `a2a card`.
7 lines
180 B
YAML
7 lines
180 B
YAML
name: agent-reviewer
|
|
version: 0.1.0
|
|
entrypoint: agent:AgentReviewer
|
|
description: Pre-deploy audit of an A2A agent's source — security, scope, ergonomics.
|
|
expose:
|
|
public: false
|