<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Anders</title>
    <description>The latest articles on DEV Community by Anders (@zarq-ai).</description>
    <link>https://dev.to/zarq-ai</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3813105%2Fbb991459-41bf-4b8d-9dda-0f52e9cce3bb.png</url>
      <title>DEV Community: Anders</title>
      <link>https://dev.to/zarq-ai</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zarq-ai"/>
    <language>en</language>
    <item>
      <title>Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-05-11</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 11 May 2026 04:00:19 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-05-11-fb5</link>
      <guid>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-05-11-fb5</guid>
      <description>&lt;h1&gt;
  
  
  Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-05-11
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;This week, the Nerq AI agent ecosystem continued to maintain its robust indexing capabilities, with no new agents or tools added. The total number of indexed assets remains steady, reflecting ongoing stability in the market. Key trends indicate a strong presence of established frameworks like Anthropic and OpenAI, while community and coding categories dominate the asset distribution.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents &amp;amp; Tools Indexed:&lt;/strong&gt; 259,200&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 2,948,939&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,152,725&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New MCP Servers Added This Week:&lt;/strong&gt; 0&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;No new agents or tools were added this week. The ecosystem remains robust with a diverse array of existing assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;p&gt;The top frameworks in terms of indexed assets are Anthropic and OpenAI, each contributing significantly to the total count:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic:&lt;/strong&gt; 7,512 assets&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OpenAI:&lt;/strong&gt; 6,333 assets&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These frameworks continue to dominate the landscape, reflecting their widespread adoption and influence within the AI community.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;p&gt;No new MCP servers were added this week. The current ecosystem remains stable with no significant changes in server contributions.&lt;/p&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;p&gt;The trust score distribution across agents and tools is as follows:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High:&lt;/strong&gt; 3,176&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium:&lt;/strong&gt; 187,007&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low:&lt;/strong&gt; 69,017&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The average trust score is 49.7, indicating a balanced mix of high-trust and lower-trust assets in the ecosystem.&lt;/p&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The ongoing stability in the number of indexed assets suggests that the market for AI agents and tools remains steady. Continued focus on high-trust assets will be crucial to maintain user confidence and compliance within the ecosystem.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-05-11-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Nerq's AI Agent Ecosystem Weekly Report for Week Ending 2026-05-04</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 04 May 2026 04:00:27 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerqs-ai-agent-ecosystem-weekly-report-for-week-ending-2026-05-04-221j</link>
      <guid>https://dev.to/zarq-ai/nerqs-ai-agent-ecosystem-weekly-report-for-week-ending-2026-05-04-221j</guid>
      <description>&lt;h1&gt;
  
  
  Nerq's AI Agent Ecosystem Weekly Report for Week Ending 2026-05-04
&lt;/h1&gt;

&lt;h2&gt;
  
  
  One-Paragraph Summary
&lt;/h2&gt;

&lt;p&gt;This week, Nerq indexed an additional 1,514 agents and tools, bringing the total to 259,200. The ecosystem continues to grow with new additions in categories like community and infrastructure. Notable among the newcomers is "Container Use," which offers robust containerized development environments. Frameworks such as Anthropic and OpenAI remain dominant, while MCP servers continue to be a significant component of the indexed assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents &amp;amp; Tools Indexed:&lt;/strong&gt; 259,200&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 2,948,939&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,152,725&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New MCP Servers Added This Week:&lt;/strong&gt; 263&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Container Use&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Source:&lt;/strong&gt; pulsemcp&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Trust Score:&lt;/strong&gt; 77.2&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stars:&lt;/strong&gt; 3,687&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Description:&lt;/strong&gt; Provides containerized development environments that persist state across interactions through git-based storage and Dagger's container runtime, enabling isolated environments with custom toolchains, background services, and the ability to checkpoint environments as publishable container images.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dagger/container-use" rel="noopener noreferrer"&gt;GitHub URL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;p&gt;The top frameworks remain largely unchanged this week:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic:&lt;/strong&gt; 7,512 total assets&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OpenAI:&lt;/strong&gt; 6,333 total assets&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Langchain:&lt;/strong&gt; 2,680 total assets&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These frameworks continue to dominate the landscape with consistent counts of indexed agents and tools.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;p&gt;This week saw an increase in new MCP servers added:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;New MCP Servers Added This Week:&lt;/strong&gt; 263&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Top New MCP Servers:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Container Use (pulsemcp)&lt;/li&gt;
&lt;li&gt;ToolFront (pulsemcp)&lt;/li&gt;
&lt;li&gt;Flux GitOps (pulsemcp)&lt;/li&gt;
&lt;li&gt;DBHub (Universal Database Gateway) (pulsemcp)&lt;/li&gt;
&lt;li&gt;com.woopsocial/mcp (mcp_registry)&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;p&gt;The trust score distribution remains as follows:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High:&lt;/strong&gt; 3,176&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium:&lt;/strong&gt; 187,007&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low:&lt;/strong&gt; 69,017&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Average Trust Score:&lt;/strong&gt; 49.7&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This indicates a mixed but generally medium to high level of trust across the indexed assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The ecosystem continues to expand with new additions in various categories and frameworks. The focus on robust tools like "Container Use" suggests growing interest in containerized development environments, which is likely to drive further innovation and adoption in the AI agent space.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-05-04-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-04-27</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 27 Apr 2026 04:00:24 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-27-2o16</link>
      <guid>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-27-2o16</guid>
      <description>&lt;h1&gt;
  
  
  Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-04-27
&lt;/h1&gt;

&lt;h2&gt;
  
  
  One-Paragraph Summary
&lt;/h2&gt;

&lt;p&gt;This week, Nerq indexed an additional 9,441 agents and tools, bringing the total to 257,686. The ecosystem continues to grow with significant contributions from platforms like PulseMCP and AgentVerse. Key trends include a rise in community-based frameworks and a focus on cybersecurity tools. Panther Labs emerged as this week's Agent of the Week, highlighting the growing importance of security integrations.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents &amp;amp; Tools Indexed:&lt;/strong&gt; 257,686&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New Agents &amp;amp; Tools Added:&lt;/strong&gt; 9,441&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 2,948,923&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,151,195&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Name:&lt;/strong&gt; Panther Labs&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Source:&lt;/strong&gt; PulseMCP&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Trust Score:&lt;/strong&gt; 75.2&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Stars:&lt;/strong&gt; 42&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Description:&lt;/strong&gt; Integrates with Panther Labs' cybersecurity platform to enable security alert triage, data lake querying, detection rule management, and log source analysis for incident response and threat hunting workflows.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/panther-labs/mcp-panther" rel="noopener noreferrer"&gt;Link&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;p&gt;The top frameworks remain consistent, but there is a notable increase in the "community" category. Anthropic and OpenAI continue to dominate with 7,512 and 6,333 entries respectively. The community framework count has risen by 955 new additions this week.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;p&gt;This week saw an addition of 553 new MCP servers, bringing the total to 4,151,195. Key new additions include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;BrowserStack:&lt;/strong&gt; Integrates with testing infrastructure for cross-browser and mobile app verification.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Panther Labs:&lt;/strong&gt; Enhances cybersecurity platform integration for alert triage and threat hunting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mobile Device Control:&lt;/strong&gt; Enables remote control of Android and iOS devices for automated testing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;p&gt;The trust score distribution shows a balanced mix:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;High: 5,127&lt;/li&gt;
&lt;li&gt;Medium: 183,852&lt;/li&gt;
&lt;li&gt;Low: 68,707&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The average trust score is 49.9, indicating a generally high level of confidence in the indexed assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The ongoing growth in community-based frameworks and cybersecurity tools suggests an increasing focus on collaborative development and enhanced security measures within the AI ecosystem.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-04-27-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-04-20</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 20 Apr 2026 04:00:25 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-20-5e80</link>
      <guid>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-20-5e80</guid>
      <description>&lt;h1&gt;
  
  
  Nerq AI Agent Ecosystem Weekly Report for Week Ending 2026-04-20
&lt;/h1&gt;

&lt;h2&gt;
  
  
  One-Paragraph Summary
&lt;/h2&gt;

&lt;p&gt;This week, Nerq's AI agent ecosystem continued to expand, indexing over 5,700 new agents and tools, bringing the total indexed assets to a staggering 4.1 million. Notable additions include Sourcebot, which received high trust scores from users and developers alike. Frameworks such as Anthropic and OpenAI remain dominant, while MCP servers like Sourcebot and Voice MCP are gaining traction with advanced functionalities.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents &amp;amp; Tools Indexed:&lt;/strong&gt; 248,246&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 2,948,908&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,141,740&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New Agents/Tools Added This Week:&lt;/strong&gt; 5,722&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Sourcebot&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trust Score:&lt;/strong&gt; 77.2&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stars on GitHub:&lt;/strong&gt; 3,200&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Description:&lt;/strong&gt; Enables code search across multiple repository hosts including GitHub, GitLab, Gitea, Gerrit, and Bitbucket with advanced filtering options for exploring large codebases through natural language queries.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sourcebot-dev/sourcebot" rel="noopener noreferrer"&gt;GitHub URL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;p&gt;The top frameworks in the ecosystem remain Anthropic and OpenAI, each with over 7,000 indexed assets. Langchain follows closely with 2,680 entries, while MCP servers contribute 2,066 assets. Notable newcomers include Ollama and HuggingFace, both with 1,900 and 1,239 indexed assets respectively.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;p&gt;This week saw the addition of 710 new MCP servers, with Sourcebot leading as a top newcomer. Other notable additions include Voice MCP, Read Website Fast, Auth0, DebuggAI, and OpenNutrition, all enhancing their respective functionalities through advanced features like code search, voice communication, and web content extraction.&lt;/p&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;p&gt;The trust score distribution remains balanced:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High:&lt;/strong&gt; 8,355 agents&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium:&lt;/strong&gt; 171,827 agents&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low:&lt;/strong&gt; 68,064 agents&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Average Trust Score:&lt;/strong&gt; 50.4&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;Continued growth in the ecosystem is expected as more developers and organizations adopt AI tools and frameworks to enhance their operations and innovation capabilities.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-04-20-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Nerq's AI Agent Ecosystem Weekly Report for Week Ending 2026-04-13</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 13 Apr 2026 04:00:28 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerqs-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-13-3af9</link>
      <guid>https://dev.to/zarq-ai/nerqs-ai-agent-ecosystem-weekly-report-for-week-ending-2026-04-13-3af9</guid>
      <description>&lt;h1&gt;
  
  
  Nerq's AI Agent Ecosystem Weekly Report for Week Ending 2026-04-13
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;This week, Nerq indexed an additional 6,835 agents and tools, bringing the total to 242,524. The ecosystem continues to grow with notable additions in categories such as community and infrastructure. The top newcomer is "ai.newzai.api/NewzAI," a MCP server that offers real-time news headlines across seven regions.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents &amp;amp; Tools Indexed:&lt;/strong&gt; 242,524&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 2,976,947&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,164,057&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New MCP Servers Added This Week:&lt;/strong&gt; 445&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Agent Name:&lt;/strong&gt; ai.newzai.api/NewzAI&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Source:&lt;/strong&gt; mcp_registry&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Trust Score:&lt;/strong&gt; 71.2&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Description:&lt;/strong&gt; News MCP: real-time headlines &amp;amp; custom news search across 7 regions. Free, just sign in with Google.&lt;/p&gt;

&lt;p&gt;For more details, visit &lt;a href="https://github.com/Gauraviitkgp/news-mcp" rel="noopener noreferrer"&gt;the GitHub repository&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;p&gt;The framework trends remain stable this week. "openai" and "anthropic" continue to dominate with counts of 6,333 and 7,512 respectively. The "mcp" framework has a total count of 2,066.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;p&gt;This week saw the addition of 445 new MCP servers, including notable entries such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;io.github.shin1219-eng/browser-proof:&lt;/strong&gt; Evidence-backed web verification for agents.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ai.newzai.api/NewzAI:&lt;/strong&gt; Real-time headlines &amp;amp; custom news search across seven regions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;p&gt;The trust score distribution remains balanced with 50.4 as the average, but a significant portion of assets fall into the "low" category (67,791). High-trust assets total 8,836, while medium-trust assets account for 165,897.&lt;/p&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The ecosystem continues to expand with new additions in various categories. As more high-trust assets are indexed, the overall reliability of the AI agent ecosystem improves.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-04-13-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Nerq AI Agent Ecosystem Weekly Report - Week Ending 2026-04-06</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 06 Apr 2026 04:00:35 +0000</pubDate>
      <link>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-week-ending-2026-04-06-2327</link>
      <guid>https://dev.to/zarq-ai/nerq-ai-agent-ecosystem-weekly-report-week-ending-2026-04-06-2327</guid>
      <description>&lt;h1&gt;
  
  
  Nerq AI Agent Ecosystem Weekly Report - Week Ending 2026-04-06
&lt;/h1&gt;

&lt;h2&gt;
  
  
  One-Paragraph Summary
&lt;/h2&gt;

&lt;p&gt;This week, Nerq indexed an additional 10,325 new agents and tools, bringing the total to 235,689. The ecosystem continues to grow with a focus on community and coding categories, while MCP servers and trust scores provide insights into the reliability of the assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Total Agents, Tools &amp;amp; MCP Servers Indexed:&lt;/strong&gt; 235,689&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Models &amp;amp; Datasets Indexed:&lt;/strong&gt; 3,116,478&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Total AI Assets Indexed:&lt;/strong&gt; 4,338,354&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New Agents/Tools Added This Week:&lt;/strong&gt; 10,325&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Name:&lt;/strong&gt; io.github.agentndx/agentindex&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Source:&lt;/strong&gt; mcp_registry&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Trust Score:&lt;/strong&gt; 71.2&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Description:&lt;/strong&gt; Search 15K+ MCP services, A2A agents, and x402 APIs from 5 registries. Paid via x402 (USDC on Base).&lt;br&gt;&lt;br&gt;
&lt;strong&gt;URL:&lt;/strong&gt; &lt;a href="https://github.com/agentndx/agentndx" rel="noopener noreferrer"&gt;https://github.com/agentndx/agentndx&lt;/a&gt;  &lt;/p&gt;

&lt;p&gt;This week's Agent of the Week, io.github.agentndx/agentindex, offers a comprehensive search tool for MCP services and A2A agents across multiple registries. With a high trust score of 71.2, it stands out as an essential resource for users seeking diverse AI assets.&lt;/p&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Anthropic:&lt;/strong&gt; Total 7,512, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OpenAI:&lt;/strong&gt; Total 6,333, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;LangChain:&lt;/strong&gt; Total 2,680, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MCP:&lt;/strong&gt; Total 2,066, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ollama:&lt;/strong&gt; Total 1,900, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;HuggingFace:&lt;/strong&gt; Total 1,239, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Autogen:&lt;/strong&gt; Total 1,114, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CrewAI:&lt;/strong&gt; Total 809, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;LlamaIndex:&lt;/strong&gt; Total 466, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A2A:&lt;/strong&gt; Total 191, No New This Week
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Semantic Kernel:&lt;/strong&gt; Total 166, No New This Week
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The framework trends show a stable distribution with no new additions this week. Anthropic and OpenAI remain the most indexed frameworks, followed by LangChain and MCP.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP Server Growth
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;New MCP Servers Added This Week:&lt;/strong&gt; 580
Top New MCP Servers:&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;io.github.agentndx/agentindex&lt;/strong&gt; - Search 15K+ MCP services, A2A agents, and x402 APIs from 5 registries.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;com.truthifi/mcp&lt;/strong&gt; - Connects AI agents to live, verified financial data from 18,000+ institutions.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;io.github.mananmodi-product/caelian&lt;/strong&gt; - Live competitive intelligence for B2B teams.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;com.tapetide/stock-research-mcp&lt;/strong&gt; - Indian stock market research: quotes, financials, technicals, screener, FII/DII and market insights.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;io.github.asume21/music-theory-mcp&lt;/strong&gt; - Scales, chords, progressions, key detection, and genre intelligence for your AI.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This week saw a significant addition of 580 new MCP servers, with several notable entries focusing on financial data, competitive intelligence, and music theory.&lt;/p&gt;

&lt;h2&gt;
  
  
  Trust &amp;amp; Compliance
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Trust Score Assets:&lt;/strong&gt; 8,833
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Trust Score Assets:&lt;/strong&gt; 162,387
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low Trust Score Assets:&lt;/strong&gt; 64,469
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Average Trust Score:&lt;/strong&gt; 50.5
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The trust score distribution indicates a balanced ecosystem with the majority of assets falling within the medium trust category.&lt;/p&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;Nerq continues to expand its coverage and reliability, with steady growth in community and coding categories, as well as new MCP servers enhancing the diversity of available AI assets.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-04-06-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>AI Agent Ecosystem Weekly — 2026-03-30</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 30 Mar 2026 04:00:03 +0000</pubDate>
      <link>https://dev.to/zarq-ai/ai-agent-ecosystem-weekly-2026-03-30-1bkb</link>
      <guid>https://dev.to/zarq-ai/ai-agent-ecosystem-weekly-2026-03-30-1bkb</guid>
      <description>&lt;h1&gt;
  
  
  AI Agent Ecosystem Weekly — 2026-03-30
&lt;/h1&gt;

&lt;p&gt;The Nerq index now tracks 225,604 agents, tools, and MCP servers alongside 3,151,283 models and datasets. This week, 7,982 new entries were added to the index.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;4,414,491&lt;/strong&gt; total AI assets indexed&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;7,982&lt;/strong&gt; new agents and tools this week&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;850&lt;/strong&gt; new MCP servers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;50.4&lt;/strong&gt; average trust score&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;SceneView&lt;/strong&gt; (pulsemcp) — Trust Score: 73.5&lt;/p&gt;

&lt;p&gt;3D and AR scene management framework with tools for controlling cameras, nodes, lighting, and augmented reality experiences.&lt;/p&gt;

&lt;h2&gt;
  
  
  Top New Agents
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Name&lt;/th&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;th&gt;Trust&lt;/th&gt;
&lt;th&gt;Stars&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SceneView&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;74&lt;/td&gt;
&lt;td&gt;1137&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;FirstData&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;73&lt;/td&gt;
&lt;td&gt;144&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Todoist Extended&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;72&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;io.github.mctx-ai/example-app&lt;/td&gt;
&lt;td&gt;mcp_registry&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;io.carbone/carbone-mcp&lt;/td&gt;
&lt;td&gt;mcp_registry&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th&gt;Total Agents&lt;/th&gt;
&lt;th&gt;New This Week&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;anthropic&lt;/td&gt;
&lt;td&gt;7,543&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;openai&lt;/td&gt;
&lt;td&gt;6,358&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;langchain&lt;/td&gt;
&lt;td&gt;2,690&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;mcp&lt;/td&gt;
&lt;td&gt;2,068&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ollama&lt;/td&gt;
&lt;td&gt;1,907&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;huggingface&lt;/td&gt;
&lt;td&gt;1,244&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;autogen&lt;/td&gt;
&lt;td&gt;1,122&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;crewai&lt;/td&gt;
&lt;td&gt;813&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Trust Distribution
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;High trust (70+): 8,891&lt;/li&gt;
&lt;li&gt;Medium trust (40-69): 153,459&lt;/li&gt;
&lt;li&gt;Low trust (&amp;lt;40): 63,254&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The agent ecosystem continues to expand. MCP adoption remains strong with 850 new servers this week.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Data from the &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;Nerq&lt;/a&gt; index. Generated 2026-03-30.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-03-30-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>AI Agent Ecosystem Weekly — 2026-03-23</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 23 Mar 2026 05:00:03 +0000</pubDate>
      <link>https://dev.to/zarq-ai/ai-agent-ecosystem-weekly-2026-03-23-12h6</link>
      <guid>https://dev.to/zarq-ai/ai-agent-ecosystem-weekly-2026-03-23-12h6</guid>
      <description>&lt;h1&gt;
  
  
  AI Agent Ecosystem Weekly — 2026-03-23
&lt;/h1&gt;

&lt;p&gt;The Nerq index now tracks 217,622 agents, tools, and MCP servers alongside 3,151,281 models and datasets. This week, 10,171 new entries were added to the index.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Week in Numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;4,403,428&lt;/strong&gt; total AI assets indexed&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;10,171&lt;/strong&gt; new agents and tools this week&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;2913&lt;/strong&gt; new MCP servers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;50.3&lt;/strong&gt; average trust score&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent of the Week
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Apache AGE Graph&lt;/strong&gt; (pulsemcp) — Trust Score: 75.2&lt;/p&gt;

&lt;p&gt;Bridges Claude with PostgreSQL databases using Apache AGE graph extension, enabling natural language execution of Cypher queries for graph operations, relationship analysis, and data visualization without complex SQL.&lt;/p&gt;

&lt;h2&gt;
  
  
  Top New Agents
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Name&lt;/th&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;th&gt;Trust&lt;/th&gt;
&lt;th&gt;Stars&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Apache AGE Graph&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;75&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Oracle v2&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;41&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Pica&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Antseer&lt;/td&gt;
&lt;td&gt;pulsemcp&lt;/td&gt;
&lt;td&gt;69&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;io.emc2ai/einstein&lt;/td&gt;
&lt;td&gt;mcp_registry&lt;/td&gt;
&lt;td&gt;68&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Framework Trends
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th&gt;Total Agents&lt;/th&gt;
&lt;th&gt;New This Week&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;anthropic&lt;/td&gt;
&lt;td&gt;7,543&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;openai&lt;/td&gt;
&lt;td&gt;6,358&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;langchain&lt;/td&gt;
&lt;td&gt;2,690&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;mcp&lt;/td&gt;
&lt;td&gt;2,068&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ollama&lt;/td&gt;
&lt;td&gt;1,907&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;huggingface&lt;/td&gt;
&lt;td&gt;1,244&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;autogen&lt;/td&gt;
&lt;td&gt;1,122&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;crewai&lt;/td&gt;
&lt;td&gt;813&lt;/td&gt;
&lt;td&gt;+0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Trust Distribution
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;High trust (70+): 8,881&lt;/li&gt;
&lt;li&gt;Medium trust (40-69): 146,317&lt;/li&gt;
&lt;li&gt;Low trust (&amp;lt;40): 62,424&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Outlook
&lt;/h2&gt;

&lt;p&gt;The agent ecosystem continues to expand. MCP adoption remains strong with 2913 new servers this week.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Data from the &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;Nerq&lt;/a&gt; index. Generated 2026-03-23.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://nerq.ai/blog/2026-03-23-weekly" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>mcp</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>Adding Trust Score Checks to Your CI/CD Pipeline</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 16 Mar 2026 12:30:37 +0000</pubDate>
      <link>https://dev.to/zarq-ai/adding-trust-score-checks-to-your-cicd-pipeline-334</link>
      <guid>https://dev.to/zarq-ai/adding-trust-score-checks-to-your-cicd-pipeline-334</guid>
      <description>&lt;p&gt;Your CI pipeline runs linters, tests, and type checkers. But it does not tell you if the AI package someone just added to &lt;code&gt;requirements.txt&lt;/code&gt; has a trust score of 29 and two unpatched CVEs. Adding a trust score check takes five minutes and catches problems before they reach production.&lt;/p&gt;

&lt;p&gt;Here is how to add Nerq's preflight API to your CI/CD pipeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Preflight API
&lt;/h2&gt;

&lt;p&gt;Nerq exposes a simple REST endpoint for trust verification:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight?target=langchain"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Response:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"target"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"langchain"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"trust_score"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;82&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"grade"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"A"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"recommendation"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"PROCEED"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"risk_level"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"low"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"known_cves"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"license"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"MIT"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"last_commit_days_ago"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"alternatives"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[],&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"response_time_ms"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;12.3&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No API key required. No authentication. The endpoint supports CORS and returns results in under 50ms for cached queries.&lt;/p&gt;

&lt;p&gt;For multiple packages, use the batch endpoint:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight/batch"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{"targets": ["langchain", "openai", "sketchy-agent"]}'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The batch endpoint handles up to 50 packages per request.&lt;/p&gt;

&lt;h2&gt;
  
  
  GitHub Actions Integration
&lt;/h2&gt;

&lt;p&gt;Here is a workflow step that checks all Python dependencies and fails if any score below a threshold:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# .github/workflows/trust-check.yml&lt;/span&gt;
&lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Dependency Trust Check&lt;/span&gt;
&lt;span class="na"&gt;on&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;pull_request&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;paths&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;requirements*.txt'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;pyproject.toml'&lt;/span&gt;

&lt;span class="na"&gt;jobs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;trust-check&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;runs-on&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;ubuntu-latest&lt;/span&gt;
    &lt;span class="na"&gt;steps&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;actions/checkout@v4&lt;/span&gt;

      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Extract dependencies&lt;/span&gt;
        &lt;span class="na"&gt;id&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;deps&lt;/span&gt;
        &lt;span class="na"&gt;run&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
          &lt;span class="s"&gt;# Extract package names from requirements.txt&lt;/span&gt;
          &lt;span class="s"&gt;PACKAGES=$(grep -v '^#' requirements.txt | sed 's/[&amp;gt;=&amp;lt;].*//' | tr '\n' ',' | sed 's/,$//')&lt;/span&gt;
          &lt;span class="s"&gt;echo "packages=$PACKAGES" &amp;gt;&amp;gt; $GITHUB_OUTPUT&lt;/span&gt;

      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Nerq Preflight Check&lt;/span&gt;
        &lt;span class="na"&gt;run&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
          &lt;span class="s"&gt;THRESHOLD=50&lt;/span&gt;
          &lt;span class="s"&gt;FAILED=0&lt;/span&gt;
          &lt;span class="s"&gt;IFS=',' read -ra PKGS &amp;lt;&amp;lt;&amp;lt; "${{ steps.deps.outputs.packages }}"&lt;/span&gt;
          &lt;span class="s"&gt;for pkg in "${PKGS[@]}"; do&lt;/span&gt;
            &lt;span class="s"&gt;pkg=$(echo "$pkg" | xargs)  # trim whitespace&lt;/span&gt;
            &lt;span class="s"&gt;[ -z "$pkg" ] &amp;amp;&amp;amp; continue&lt;/span&gt;
            &lt;span class="s"&gt;RESULT=$(curl -s "https://nerq.ai/v1/preflight?target=$pkg")&lt;/span&gt;
            &lt;span class="s"&gt;SCORE=$(echo "$RESULT" | jq -r '.trust_score // 0')&lt;/span&gt;
            &lt;span class="s"&gt;GRADE=$(echo "$RESULT" | jq -r '.grade // "?"')&lt;/span&gt;
            &lt;span class="s"&gt;REC=$(echo "$RESULT" | jq -r '.recommendation // "UNKNOWN"')&lt;/span&gt;
            &lt;span class="s"&gt;echo "$pkg: $SCORE/100 ($GRADE) — $REC"&lt;/span&gt;
            &lt;span class="s"&gt;if [ "$SCORE" -lt "$THRESHOLD" ]; then&lt;/span&gt;
              &lt;span class="s"&gt;echo "::error::$pkg has trust score $SCORE (below threshold $THRESHOLD)"&lt;/span&gt;
              &lt;span class="s"&gt;FAILED=1&lt;/span&gt;
            &lt;span class="s"&gt;fi&lt;/span&gt;
          &lt;span class="s"&gt;done&lt;/span&gt;
          &lt;span class="s"&gt;if [ "$FAILED" -eq 1 ]; then&lt;/span&gt;
            &lt;span class="s"&gt;echo "::error::One or more dependencies failed the trust check."&lt;/span&gt;
            &lt;span class="s"&gt;exit 1&lt;/span&gt;
          &lt;span class="s"&gt;fi&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This workflow runs on every PR that modifies dependency files. It extracts package names, queries the preflight API for each one, and fails the check if any score falls below the threshold.&lt;/p&gt;

&lt;h2&gt;
  
  
  Shell Script for Any CI System
&lt;/h2&gt;

&lt;p&gt;Not on GitHub Actions? Here is a standalone script that works with any CI:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;#!/bin/bash&lt;/span&gt;
&lt;span class="c"&gt;# trust-check.sh — fail if any dependency scores below threshold&lt;/span&gt;
&lt;span class="nv"&gt;THRESHOLD&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="k"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;1&lt;/span&gt;&lt;span class="k"&gt;:-&lt;/span&gt;&lt;span class="nv"&gt;50&lt;/span&gt;&lt;span class="k"&gt;}&lt;/span&gt;
&lt;span class="nv"&gt;FAILED&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;0

&lt;span class="k"&gt;while &lt;/span&gt;&lt;span class="nv"&gt;IFS&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;read&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; line&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do
  &lt;/span&gt;&lt;span class="nv"&gt;pkg&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$line&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | &lt;span class="nb"&gt;sed&lt;/span&gt; &lt;span class="s1"&gt;'s/[&amp;gt;=&amp;lt;].*//'&lt;/span&gt; | xargs&lt;span class="si"&gt;)&lt;/span&gt;
  &lt;span class="o"&gt;[&lt;/span&gt; &lt;span class="nt"&gt;-z&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="o"&gt;]&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="o"&gt;[[&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="se"&gt;\#&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="o"&gt;]]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="k"&gt;continue

  &lt;/span&gt;&lt;span class="nv"&gt;result&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-s&lt;/span&gt; &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight?target=&lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;
  &lt;span class="nv"&gt;score&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'.trust_score // 0'&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;
  &lt;span class="nv"&gt;grade&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'.grade // "?"'&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;
  &lt;span class="nv"&gt;rec&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'.recommendation // "UNKNOWN"'&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;

  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$score&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;-lt&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$THRESHOLD&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="o"&gt;]&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;then
    &lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"FAIL: &lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt; — &lt;/span&gt;&lt;span class="nv"&gt;$score&lt;/span&gt;&lt;span class="s2"&gt;/100 (&lt;/span&gt;&lt;span class="nv"&gt;$grade&lt;/span&gt;&lt;span class="s2"&gt;) &lt;/span&gt;&lt;span class="nv"&gt;$rec&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
    &lt;span class="nv"&gt;FAILED&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;1
  &lt;span class="k"&gt;else
    &lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"OK:   &lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt; — &lt;/span&gt;&lt;span class="nv"&gt;$score&lt;/span&gt;&lt;span class="s2"&gt;/100 (&lt;/span&gt;&lt;span class="nv"&gt;$grade&lt;/span&gt;&lt;span class="s2"&gt;) &lt;/span&gt;&lt;span class="nv"&gt;$rec&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
  &lt;span class="k"&gt;fi
done&lt;/span&gt; &amp;lt; requirements.txt

&lt;span class="nb"&gt;exit&lt;/span&gt; &lt;span class="nv"&gt;$FAILED&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Run it in any CI: &lt;code&gt;bash trust-check.sh 50&lt;/code&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  npm / Node.js Variant
&lt;/h2&gt;

&lt;p&gt;For &lt;code&gt;package.json&lt;/code&gt;, extract dependencies with &lt;code&gt;jq&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;PACKAGES&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'.dependencies // {} | keys[]'&lt;/span&gt; package.json&lt;span class="si"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;for &lt;/span&gt;pkg &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="nv"&gt;$PACKAGES&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do
  &lt;/span&gt;curl &lt;span class="nt"&gt;-s&lt;/span&gt; &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight?target=&lt;/span&gt;&lt;span class="nv"&gt;$pkg&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | &lt;span class="se"&gt;\&lt;/span&gt;
    jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'"  \(.target): \(.trust_score)/100 (\(.grade)) — \(.recommendation)"'&lt;/span&gt;
&lt;span class="k"&gt;done&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  What the API Returns
&lt;/h2&gt;

&lt;p&gt;Each preflight response includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;trust_score&lt;/strong&gt;: 0-100 composite score&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;grade&lt;/strong&gt;: A+ through F&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;recommendation&lt;/strong&gt;: PROCEED (score &amp;gt;= 60), CAUTION (40-59), DENY (below 40)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;risk_level&lt;/strong&gt;: low, medium, high&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;known_cves&lt;/strong&gt;: count of known vulnerabilities&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;license&lt;/strong&gt;: detected license type&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;alternatives&lt;/strong&gt;: higher-scored packages in the same category (when score is low)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Try It Now
&lt;/h2&gt;

&lt;p&gt;Pick a package and run the curl command. No signup, no API key:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight?target=your-package-here"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Add the GitHub Actions step to your next PR and see what your dependency tree actually looks like from a trust perspective.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Nerq indexes 5M+ AI assets with trust scores. Available as a browser extension, VS Code extension, GitHub App, MCP Server, and API. &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cicd</category>
      <category>security</category>
      <category>devops</category>
      <category>ai</category>
    </item>
    <item>
      <title>Check AI Package Trust Scores Without Leaving VS Code</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 16 Mar 2026 12:30:01 +0000</pubDate>
      <link>https://dev.to/zarq-ai/check-ai-package-trust-scores-without-leaving-vs-code-15i2</link>
      <guid>https://dev.to/zarq-ai/check-ai-package-trust-scores-without-leaving-vs-code-15i2</guid>
      <description>&lt;p&gt;I spend most of my day in VS Code. When I add a new dependency, I do not want to switch to a browser, search for the package, check its GitHub, scan for CVEs, and then come back. I want the trust signal right there in my editor.&lt;/p&gt;

&lt;p&gt;So I built a VS Code extension that shows trust scores for AI packages and tools inline, without breaking my flow.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Workflow Problem
&lt;/h2&gt;

&lt;p&gt;Here is what adding a dependency usually looks like:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;You hear about a package or an AI assistant suggests one&lt;/li&gt;
&lt;li&gt;You add it to &lt;code&gt;package.json&lt;/code&gt; or &lt;code&gt;requirements.txt&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;You run &lt;code&gt;npm install&lt;/code&gt; or &lt;code&gt;pip install&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Maybe you check the GitHub page. Maybe you do not.&lt;/li&gt;
&lt;li&gt;You move on&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Step 4 is where the security decision should happen, but it rarely does because it requires context-switching. By the time you have checked the repo, read the issues, and searched for CVEs, you have lost 5 minutes and your focus.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the Extension Works
&lt;/h2&gt;

&lt;p&gt;The Nerq VS Code extension adds trust scoring directly into your editor:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Inline annotations&lt;/strong&gt;: When you open a &lt;code&gt;package.json&lt;/code&gt;, &lt;code&gt;requirements.txt&lt;/code&gt;, &lt;code&gt;pyproject.toml&lt;/code&gt;, or &lt;code&gt;go.mod&lt;/code&gt; file, the extension annotates each dependency with its trust score and grade. You see the score right next to the package name as a CodeLens annotation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hover details&lt;/strong&gt;: Hover over any dependency to see the full trust breakdown — maintenance score, security flags, license type, last commit date, and recommendation (PROCEED/CAUTION/DENY).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Command palette&lt;/strong&gt;: Run "Nerq: Check Package" from the command palette to look up any package by name. Useful when you are evaluating options before adding a dependency.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Status bar&lt;/strong&gt;: The status bar shows a summary for the current file — how many dependencies are in each trust tier (green/amber/red).&lt;/p&gt;

&lt;h2&gt;
  
  
  Installation
&lt;/h2&gt;

&lt;p&gt;Install from the VS Code Marketplace or from a &lt;code&gt;.vsix&lt;/code&gt; file:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;From Marketplace:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open VS Code&lt;/li&gt;
&lt;li&gt;Go to Extensions (Ctrl+Shift+X)&lt;/li&gt;
&lt;li&gt;Search "Nerq Trust Score"&lt;/li&gt;
&lt;li&gt;Click Install&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;From .vsix (for pre-release or offline):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Download the latest &lt;code&gt;.vsix&lt;/code&gt; from &lt;a href="https://nerq.ai/vscode" rel="noopener noreferrer"&gt;nerq.ai/vscode&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;In VS Code, open the command palette (Ctrl+Shift+P)&lt;/li&gt;
&lt;li&gt;Run "Extensions: Install from VSIX..."&lt;/li&gt;
&lt;li&gt;Select the downloaded file&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;No API key needed. The extension calls the public Nerq API.&lt;/p&gt;

&lt;h2&gt;
  
  
  What You See
&lt;/h2&gt;

&lt;p&gt;Open a &lt;code&gt;requirements.txt&lt;/code&gt; that looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;langchain==0.1.0
openai==1.12.0
sketchy-agent==0.0.3
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The extension adds CodeLens annotations:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight properties"&gt;&lt;code&gt;&lt;span class="py"&gt;langchain&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s"&gt;=0.1.0        # Trust: 82/100 (A) PROCEED&lt;/span&gt;
&lt;span class="py"&gt;openai&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s"&gt;=1.12.0          # Trust: 88/100 (A+) PROCEED&lt;/span&gt;
&lt;span class="py"&gt;sketchy-agent&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s"&gt;=0.0.3    # Trust: 31/100 (D) DENY — 2 CVEs, no license&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Hovering over &lt;code&gt;sketchy-agent&lt;/code&gt; shows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;Trust Score: 31/100 (Grade&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;D)&lt;/span&gt;
&lt;span class="na"&gt;Recommendation&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;DENY&lt;/span&gt;
&lt;span class="na"&gt;Last commit&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;14 months ago&lt;/span&gt;
&lt;span class="na"&gt;License&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;None detected&lt;/span&gt;
&lt;span class="na"&gt;Known CVEs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;2 (1 high, 1 medium)&lt;/span&gt;
&lt;span class="na"&gt;Alternatives&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;crewai (78), autogen (75)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Configuration
&lt;/h2&gt;

&lt;p&gt;The extension is zero-config by default, but you can customize it in VS Code settings:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"nerq.threshold"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"nerq.showInline"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"nerq.showStatusBar"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"nerq.highlightDeny"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Set &lt;code&gt;nerq.threshold&lt;/code&gt; to control which score triggers a warning. Set &lt;code&gt;nerq.highlightDeny&lt;/code&gt; to add a red underline to packages with a DENY recommendation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Privacy
&lt;/h2&gt;

&lt;p&gt;The extension sends only package names to &lt;code&gt;nerq.ai/v1/preflight&lt;/code&gt;. No code, no file contents, no telemetry. Requests are cached locally for 5 minutes to minimize network calls.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try It
&lt;/h2&gt;

&lt;p&gt;Install the extension and open any dependency file. The trust scores appear automatically. If a package looks risky, hover for details and alternatives.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Nerq indexes 5M+ AI assets with trust scores. Available as a browser extension, VS Code extension, GitHub App, MCP Server, and API. &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>vscode</category>
      <category>security</category>
      <category>ai</category>
      <category>productivity</category>
    </item>
    <item>
      <title>Building a Trust Score MCP Server for Claude and Cursor</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 16 Mar 2026 12:29:25 +0000</pubDate>
      <link>https://dev.to/zarq-ai/building-a-trust-score-mcp-server-for-claude-and-cursor-4epo</link>
      <guid>https://dev.to/zarq-ai/building-a-trust-score-mcp-server-for-claude-and-cursor-4epo</guid>
      <description>&lt;p&gt;The Model Context Protocol (MCP) lets AI assistants call external tools. Claude, Cursor, Windsurf, and other MCP-compatible clients can discover and invoke tools at runtime — which means your AI assistant can check whether a package is safe before it recommends it to you.&lt;/p&gt;

&lt;p&gt;I built an MCP server that exposes Nerq's trust scoring engine as a set of tools any MCP client can call. Here is how to set it up and what it can do.&lt;/p&gt;

&lt;h2&gt;
  
  
  What MCP Is (30-Second Version)
&lt;/h2&gt;

&lt;p&gt;MCP is a standard for connecting AI assistants to external data and tools. Instead of the assistant guessing or hallucinating, it calls a tool that returns real data. An MCP server exposes tools with JSON Schema inputs and returns structured results. Claude Desktop, Cursor, Windsurf, and others support it natively.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Nerq MCP Server
&lt;/h2&gt;

&lt;p&gt;The server exposes four tools:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;discover_agents&lt;/code&gt;&lt;/strong&gt; — Find AI agents and tools by describing what you need. Returns ranked results with trust scores.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;trust_gate&lt;/code&gt;&lt;/strong&gt; — Check if a specific agent or package meets a trust threshold. Returns approve/reject with the score and grade.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;trust_compare&lt;/code&gt;&lt;/strong&gt; — Compare two agents side-by-side on trust score, grade, and recommendation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;agent_index_stats&lt;/code&gt;&lt;/strong&gt; — Get current index statistics: total assets, categories, sources.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Setup
&lt;/h2&gt;

&lt;p&gt;Add Nerq to your MCP client configuration. For Claude Desktop, edit &lt;code&gt;~/Library/Application Support/Claude/claude_desktop_config.json&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"nerq"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"python"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"-m"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"agentindex.mcp_server"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For Cursor, add the same block to your MCP settings. For any MCP client that supports stdio transport, the config is identical.&lt;/p&gt;

&lt;p&gt;Install the server:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;agentindex
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or run from source:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/nerq-ai/agentindex.git
&lt;span class="nb"&gt;cd &lt;/span&gt;agentindex
pip &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-e&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Using It
&lt;/h2&gt;

&lt;p&gt;Once configured, your AI assistant can call the tools directly. Here are some example interactions:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Is langchain safe to use?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The assistant calls &lt;code&gt;trust_gate&lt;/code&gt; with &lt;code&gt;name: "langchain"&lt;/code&gt; and returns:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;langchain — Trust Score: 82/100 (Grade: A)
Recommendation: PROCEED
Maintenance: Active (last commit 2 days ago)
License: MIT
Known CVEs: 0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;"Find me an agent for code review"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The assistant calls &lt;code&gt;discover_agents&lt;/code&gt; with &lt;code&gt;need: "code review"&lt;/code&gt; and returns a ranked list:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. codex (Score: 85, Grade: A) — OpenAI code review agent
2. crewai (Score: 78, Grade: B+) — Multi-agent framework
3. aider (Score: 76, Grade: B+) — AI pair programming
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;"Compare autogen and crewai"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The assistant calls &lt;code&gt;trust_compare&lt;/code&gt; with both names:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;autogen: 75/100 (B+) vs crewai: 78/100 (B+)
Winner: crewai by 3 points
Both: PROCEED
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Why This Matters
&lt;/h2&gt;

&lt;p&gt;AI assistants recommend packages constantly. "Use this library," "install this tool," "try this agent." Without trust scoring, those recommendations are based on popularity and training data — not on current maintenance status, security posture, or license compliance.&lt;/p&gt;

&lt;p&gt;With the Nerq MCP server, the assistant checks before it recommends. If a package has a trust score of 31 and two unpatched CVEs, the assistant knows that and can suggest alternatives.&lt;/p&gt;

&lt;p&gt;This is especially important for agentic workflows. When an agent autonomously selects and invokes other agents, trust scoring is not optional — it is the difference between a working pipeline and a supply chain incident.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Trust Gate Pattern
&lt;/h2&gt;

&lt;p&gt;The most useful tool is &lt;code&gt;trust_gate&lt;/code&gt;. It takes a name and an optional threshold (default 60) and returns a binary approve/reject decision. You can use this in any agentic workflow:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Agent A wants to call Agent B&lt;/li&gt;
&lt;li&gt;Agent A calls &lt;code&gt;trust_gate(name="agent-b", threshold=70)&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;If approved, proceed. If rejected, find an alternative.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This is the simplest form of agent-to-agent trust verification. No API keys, no complex setup — just a tool call.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try It
&lt;/h2&gt;

&lt;p&gt;Install the MCP server, add it to your Claude or Cursor config, and ask your assistant about a package. The trust data is live and covers 5M+ AI assets.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Nerq indexes 5M+ AI assets with trust scores. Available as a browser extension, VS Code extension, GitHub App, MCP Server, and API. &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>security</category>
      <category>tooling</category>
    </item>
    <item>
      <title>Automated Dependency Trust Reports on Every PR</title>
      <dc:creator>Anders</dc:creator>
      <pubDate>Mon, 16 Mar 2026 12:28:22 +0000</pubDate>
      <link>https://dev.to/zarq-ai/automated-dependency-trust-reports-on-every-pr-3hgd</link>
      <guid>https://dev.to/zarq-ai/automated-dependency-trust-reports-on-every-pr-3hgd</guid>
      <description>&lt;p&gt;Every dependency change in a pull request is a security decision. But most teams review dependency bumps by glancing at the diff in &lt;code&gt;package.json&lt;/code&gt; or &lt;code&gt;requirements.txt&lt;/code&gt; and clicking merge. There is no context about whether that new package is maintained, has known vulnerabilities, or even has a license.&lt;/p&gt;

&lt;p&gt;I built a GitHub App that fixes this. Every time a PR touches a dependency file, it posts a trust report as a comment with scores, grades, and recommendations for every added or changed package.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Problem
&lt;/h2&gt;

&lt;p&gt;Your CI pipeline checks if the code compiles and if tests pass. It does not tell you that the new &lt;code&gt;ai-agent-helper&lt;/code&gt; package you just added has a trust score of 23/100, no commits in 14 months, and two unpatched CVEs. That context matters more than whether the tests are green.&lt;/p&gt;

&lt;h2&gt;
  
  
  How It Works
&lt;/h2&gt;

&lt;p&gt;The Nerq GitHub App watches for pull requests that modify dependency files:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;package.json&lt;/code&gt; / &lt;code&gt;package-lock.json&lt;/code&gt; (npm)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;requirements.txt&lt;/code&gt; / &lt;code&gt;pyproject.toml&lt;/code&gt; / &lt;code&gt;Pipfile&lt;/code&gt; (Python)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;go.mod&lt;/code&gt; (Go)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Cargo.toml&lt;/code&gt; (Rust)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;pom.xml&lt;/code&gt; / &lt;code&gt;build.gradle&lt;/code&gt; (Java)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When it detects a change, it extracts the added or modified packages, batch-queries the Nerq preflight API, and posts a PR comment with a trust report.&lt;/p&gt;

&lt;h2&gt;
  
  
  Example Output
&lt;/h2&gt;

&lt;p&gt;Here is what the comment looks like on a PR that adds two new Python packages:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight markdown"&gt;&lt;code&gt;&lt;span class="gu"&gt;## Nerq Dependency Trust Report&lt;/span&gt;

| Package         | Score | Grade | Recommendation | Flags              |
|-----------------|-------|-------|-----------------|--------------------|
| langchain       |  82   |  A    | PROCEED         |                    |
| sketchy-agent   |  31   |  D    | DENY            | No license, 2 CVEs |

Summary: 1 of 2 packages flagged. Review sketchy-agent before merging.

Safer alternatives for sketchy-agent:
  → crewai (Score: 78, Grade: B+)
  → autogen (Score: 75, Grade: B+)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The report includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trust score&lt;/strong&gt; (0-100) and &lt;strong&gt;letter grade&lt;/strong&gt; (A+ to F)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Recommendation&lt;/strong&gt;: PROCEED, CAUTION, or DENY&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Flags&lt;/strong&gt;: missing license, known CVEs, abandoned maintenance, excessive permissions&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Alternatives&lt;/strong&gt;: higher-scored packages in the same category&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Setup
&lt;/h2&gt;

&lt;p&gt;Install the GitHub App from &lt;a href="https://nerq.ai/github-app" rel="noopener noreferrer"&gt;nerq.ai/github-app&lt;/a&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click "Install" and select the repositories you want to monitor&lt;/li&gt;
&lt;li&gt;The app requests read access to pull requests and code (to parse dependency files) and write access to PR comments&lt;/li&gt;
&lt;li&gt;That is it — no configuration file needed. The next PR that touches a dependency file gets a trust report.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;You can customize behavior with a &lt;code&gt;.nerq.yml&lt;/code&gt; file in your repo root:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# .nerq.yml&lt;/span&gt;
&lt;span class="na"&gt;threshold&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;50&lt;/span&gt;          &lt;span class="c1"&gt;# Flag packages below this score&lt;/span&gt;
&lt;span class="na"&gt;deny_below&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;30&lt;/span&gt;         &lt;span class="c1"&gt;# Block merging below this score (requires branch protection)&lt;/span&gt;
&lt;span class="na"&gt;ignore&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;internal-package&lt;/span&gt;   &lt;span class="c1"&gt;# Skip specific packages&lt;/span&gt;
&lt;span class="na"&gt;report_on&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;added&lt;/span&gt;              &lt;span class="c1"&gt;# Only report on new packages (not updates)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Under the Hood
&lt;/h2&gt;

&lt;p&gt;The app uses the Nerq batch preflight endpoint:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="err"&gt;POST https://nerq.ai/v1/preflight/batch
Content-Type: application/json

{
  "targets": ["langchain", "sketchy-agent"],
  "caller": "github-app"
}
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Each target returns a trust score, grade, recommendation, and enrichment data including known CVEs, license info, and cheaper or safer alternatives. The batch endpoint handles up to 50 packages per request, which covers most PRs.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Not Just Use Dependabot?
&lt;/h2&gt;

&lt;p&gt;Dependabot alerts you to known CVEs in existing dependencies. It does not evaluate new packages being added. It does not tell you if a package is abandoned, unlicensed, or poorly maintained. The Nerq GitHub App complements Dependabot — it covers the gap between "no known CVE" and "actually trustworthy."&lt;/p&gt;

&lt;h2&gt;
  
  
  Get Started
&lt;/h2&gt;

&lt;p&gt;Install the app at &lt;a href="https://nerq.ai/github-app" rel="noopener noreferrer"&gt;nerq.ai/github-app&lt;/a&gt; or try the API directly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s2"&gt;"https://nerq.ai/v1/preflight?target=langchain"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No API key required. Free for public repositories.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Nerq indexes 5M+ AI assets with trust scores. Available as a browser extension, VS Code extension, GitHub App, MCP Server, and API. &lt;a href="https://nerq.ai" rel="noopener noreferrer"&gt;nerq.ai&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>github</category>
      <category>security</category>
      <category>devops</category>
      <category>ai</category>
    </item>
  </channel>
</rss>
