fast-agent

Code, Build and Evaluate agents - excellent Model and Skills/MCP/ACP Support

Agent Frameworks Python Grade C Listed Apache-2.0
62.2/100
Rank #187 of 468
Compare fast-agent

Promising trust profile, but some evidence still deserves review.

Open compare tool Suggest correction
Listing state
Listed
Evidence coverage
Grade C · 2/5 signals
Last push
2026-08-05 · 1d ago
Recent change
No recent signal change

Is fast-agent safe? fast-agent scores 62.2/100 (Grade C), ranked #187 of 468 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types). The public evidence: no package-provenance attestation found; OSSF Scorecard rates its supply-chain practices 5.9/10; 60% of recent commits are signed; last pushed 2026-08-05. Every point is earned from checkable signals — never paid placement. How scoring works →

Ranked neighbours in Agent Frameworks

Quick Trust Read

What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-07-14
Rank Moved
Rank dropped 15 spots (#171 → #186)
2026-07-13
Rank Moved
Rank dropped 20 spots (#151 → #171)
Maintainer Checklist
Raise Scorecard signals Current OSSF Scorecard is 5.9/10. Tighten the weakest checks to improve public safety evidence.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
81.2
Activity sub-score · out of 100
#37

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade C reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-08-06 05:00 UTC · Repo last pushed yesterday

Rank Trend

2026-07-05 2026-08-06

Activity & Reach

Stars
3.9k
Forks
424
Last Push
2026-08-05
yesterday
Commits (4 wk)
63
Downloads (7d)
HN mentions (30d)
Open Issues
18
Rank Change
=
was #187

Analysis

HVTrust Dimensions vs Agent Frameworks

62.2 / 100 · 100.0% confidence

fast-agent Agent Frameworks average (103 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
10.4 / 25
1.4 above avg 9.0
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
0.9 below avg 11.7
Transparency50% declared license · 50% OSSF Scorecard
13.5 / 17
1.5 above avg 12.0
Maintenance60% last-push freshness · 40% commit activity
19.1 / 20
4.5 above avg 14.6
AdoptionLog-scaled stars · package downloads
8.6 / 20
3.3 below avg 11.9

Activity Inputs

81.2 / 100
StarsRepository reach
21.5 / 30
FreshnessLast push recency
24.9 / 25
ActivityRecent commits
22.5 / 25
CommunityFork signal
12.2 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
5.9 / 10
OpenSSF Scorecard · scanned Jul 11, 2026 (refresh pending)
Signed Commits
60%
of last 100 commits verified
Binary-Artifacts 10
Branch-Protection 3
CI-Tests 10
CII-Best-Practices 0
Code-Review 2
Contributors 10
Dangerous-Workflow 10
Dependency-Update-Tool 10
Fuzzing 0
License 10
Maintained 10
Packaging -1
Pinned-Dependencies 0
SAST 7
Security-Policy 0
Signed-Releases -1
Token-Permissions 0
Vulnerabilities 10

Is fast-agent safe?

fast-agent has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does fast-agent publish package provenance?
No published build provenance is currently detected for fast-agent. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does fast-agent have an OpenSSF Scorecard?
fast-agent has an OpenSSF Scorecard score of 5.9/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is fast-agent actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does fast-agent use?
fast-agent ships under Apache-2.0. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are fast-agent's commits signed?
60% of the last 100 commits to fast-agent are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
high confidence
Implemented
fast-agent appears to expose MCP server capabilities.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
3 detected
Public provider/service dependencies detected.
Credential signal: No explicit API-key/config marker detected.
Tool / Plugin Surface
high confidence
Declared
Declared plugin/integration surface detected.
  • code
  • filesystem
  • shell
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live

Maintain fast-agent?

For maintainers

HVTrust scores fast-agent from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Rank 5Listed 1HVTrust 1Grade 1Scorecard 1
2026-07-14
Rank Moved
Rank dropped 15 spots (#171 → #186)
2026-07-13
Rank Moved
Rank dropped 20 spots (#151 → #171)
2026-06-24
Scorecard Added
OSSF Scorecard: 5.4/10
2026-06-24
Grade Changed
Trust grade D → C
2026-06-24
Rank Moved
Rank rose 110 spots (#285 → #175)
2026-06-24
HVTrust Changed
HVTrust up 35.9pts (24.4 → 60.3)
2026-06-23
Rank Moved
Rank dropped 18 spots (#267 → #285)
2026-06-21
Rank Moved
Rank dropped 15 spots (#248 → #263)
2026-06-20
Newly Listed
First tracked at rank #248

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 62.2 Grade C
Markdown:
[![HVTrust](https://hvtracker.net/badge/fast-agent.svg)](https://hvtracker.net/agents/fast-agent)
HTML:
<a href="https://hvtracker.net/agents/fast-agent"><img src="https://hvtracker.net/badge/fast-agent.svg" alt="HVTrust"></a>

Other agents in Agent Frameworks

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.2 · Raw JSON