stoa-agent-risk is a local-first command-line tool that performs static analysis to discover AI agent candidates in codebases. It provides evidence for each finding, maps out agent capabilities and third-party integrations, and identifies newly introduced high-confidence critical risks. Designed for security-conscious developers and teams working with LLMs and autonomous agents, it helps maintain an up-to-date inventory and prevent risky agent deployments.
stoa-agent-risk is a LLM eval & observability product. Manually discovering, inventorying, and assessing security risks of AI agents and LLM integrations in a codebase. stoa-agent-risk is an open-source project aimed at developers. The project is open source (MIT). It runs on the command line, and it can be self-hosted.
Behind stoa-agent-risk is iamved, and the product first shipped in 2026. The project is developed in the open on GitHub with 2 commits in the last 90 days. Among its 6 catalogued features are Agent Discovery, Risk Scanning, and Capability Mapping.
Latest indexed changes and source events
stoa-agent-risk verified by the PulseGate indexer
Other apps tracked under the same category.