Is AG-UI safe?
AG-UI scores 66.2/100 (Grade B), ranked #140 of 441 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types).
The public evidence: no package-provenance attestation found;
OSSF Scorecard rates its supply-chain practices 6.9/10;
65% of recent commits are signed;
last pushed 2026-07-28. Every point is earned from checkable signals — never paid placement. How scoring works →
Quick Trust Read
Verdict
Promising trust profile, but some evidence still deserves review.
66.2/100 · Grade B
Strongest Signal
Maintenance
19.9/20
Weakest Signal
Safety / Integrity
11.9/25
What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-07-28
Newly Listed
First tracked at rank #140
Maintainer Checklist
Raise Scorecard signalsCurrent OSSF Scorecard is 6.9/10. Tighten the weakest checks to improve public safety evidence.
Publish provenanceAdd package provenance or release attestations so users can verify where shipped artifacts came from.
How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade B reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →
Signals refreshed2026-07-29 01:00 UTC·Repo last pushed yesterday
AG-UI has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does AG-UI publish package provenance?
No published build provenance is currently detected for AG-UI. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does AG-UI have an OpenSSF Scorecard?
AG-UI has an OpenSSF Scorecard score of 6.9/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is AG-UI actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does AG-UI use?
AG-UI ships under MIT. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are AG-UI's commits signed?
65% of the last 100 commits to AG-UI are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.
Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.
These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →
MCP Server Support
None detected
No MCP server signal detected.
Detailed evidence is not shown in the public view.
Credential signal:
No explicit API-key/config marker detected.
Tool / Plugin Surface
medium confidence
Declared
Declared plugin/integration surface detected.
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
MCP signal live
External deps live
Tool / plugin surface live
Package provenance drift live
Maintain AG-UI?
HVTrust scores AG-UI from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.
Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.2 · Raw JSON