zylon-ai · PrivateGPT

Complete API layer for private AI applications on local models: RAG, skills, tools, MCP, text-to-sql, and more. Works wi

Agent Frameworks Python Grade D Listed Apache-2.0
22.8/100
Rank #1311 of 1328
Compare zylon-ai · PrivateGPT

How does it stack up against its Agent Frameworks neighbours?

Pick any agent to compare →

Thin or incomplete trust evidence. Review carefully before production use.

Open compare tool Suggest correction
Listing state
Listed
Evidence coverage
Grade D · 1/5 signals
Last push
2026-09-08 · 0d ago
Recent change
New

Is zylon-ai · PrivateGPT safe? zylon-ai · PrivateGPT scores 22.8/100 (Grade D), ranked #1311 of 1328 tracked open-source AI agent projects, on evidence coverage D (1 of 5 independent signal types). The public evidence: no package-provenance attestation found; no OSSF Scorecard result yet; 100% of recent commits are signed; last pushed 2026-09-08. Every point is earned from checkable signals — never paid placement. How scoring works →

Ranked neighbours in Agent Frameworks

Quick Trust Read

What Would Improve It
Add or improve OSSF Scorecard coverage so safety checks are easier to verify.
Recent Changes
2026-09-08
Newly Listed
First tracked at rank #1311
Maintainer Checklist
Add Scorecard coverage Expose the repository to OpenSSF Scorecard checks so supply-chain posture is easier to verify.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
88.1
Activity sub-score · out of 100
#120

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade D reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage D is separate — it grades how many independent signal types back the score (1 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-09-08 14:33 UTC · Repo last pushed today

Activity & Reach

Stars
57.5k
Forks
7.6k
Last Push
2026-09-08
today
Commits (4 wk)
20
Downloads (7d)
HN mentions (30d)
Open Issues
1
Rank Change
NEW

Analysis

HVTrust Dimensions vs Agent Frameworks

22.8 / 100 · 50.0% confidence

zylon-ai · PrivateGPT Agent Frameworks average (122 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
5.0 / 25
4.5 below avg 9.5
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
0.8 below avg 11.6
Transparency50% declared license · 50% OSSF Scorecard
8.5 / 17
3.8 below avg 12.3
Maintenance60% last-push freshness · 40% commit activity
17.3 / 20
3.3 above avg 14.0
AdoptionLog-scaled stars · package downloads
11.4 / 20
in line with avg 11.2

Activity Inputs

88.1 / 100
StarsRepository reach
28.6 / 30
FreshnessLast push recency
25.0 / 25
ActivityRecent commits
16.5 / 25
CommunityFork signal
18.0 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
Not available
Signed Commits
100%
of last 100 commits verified

Is zylon-ai · PrivateGPT safe?

Public trust evidence for zylon-ai · PrivateGPT is thin: several supply-chain signals are missing or weak. This does not mean the project is unsafe — it means an outside observer cannot easily verify the usual integrity checks. Treat with extra scrutiny.
Does zylon-ai · PrivateGPT publish package provenance?
No published build provenance is currently detected for zylon-ai · PrivateGPT. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does zylon-ai · PrivateGPT have an OpenSSF Scorecard?
No OpenSSF Scorecard data is currently published for zylon-ai · PrivateGPT. Maintainers can enable the Scorecard GitHub Action to get a public score; without it, automated supply-chain hygiene is harder for outsiders to verify.
Is zylon-ai · PrivateGPT actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does zylon-ai · PrivateGPT use?
zylon-ai · PrivateGPT ships under Apache-2.0. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are zylon-ai · PrivateGPT's commits signed?
100% of the last 100 commits to zylon-ai · PrivateGPT are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
None detected
No MCP server signal detected.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
6 detected
Public provider/service dependencies detected.
Credential signal: No explicit API-key/config marker detected.
Tool / Plugin Surface
high confidence
Extensions
Extension based plugin/integration surface detected.
  • browser
  • database
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live

Maintain zylon-ai · PrivateGPT?

For maintainers

HVTrust scores zylon-ai · PrivateGPT from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Listed 1
2026-09-08
Newly Listed
First tracked at rank #1311

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 22.8 Grade D
Markdown:
[![HVTrust](https://hvtracker.net/badge/zylon-ai-privategpt.svg)](https://hvtracker.net/agents/zylon-ai-privategpt)
HTML:
<a href="https://hvtracker.net/agents/zylon-ai-privategpt"><img src="https://hvtracker.net/badge/zylon-ai-privategpt.svg" alt="HVTrust"></a>

Other agents in Agent Frameworks

Data sources
GitHub REST API (repo, commits, stars, forks, license)
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON