Research behind CraftedTrust

Touchstone Research

Touchstone research powers the deeper checks behind public registry scores and publisher reviews.

8134
Registry Coverage
9
Published Advisories
27
Disclosure Cases
63
Checks Behind Scores

Published Advisories

Subscribe via RSS

Checks Behind Registry Findings

63 checks feed 12 public score categories.

Full Check Reference
Authentication & Authorization 9 checks

OAuth 2.1 implementation, PKCE enforcement, token storage, HTTPS enforcement, scope analysis, session management, RFC 8707 compliance.

Tool Security 10 checks

Prompt injection in tool schemas, parameter poisoning, obfuscated payloads, tool shadowing, rug pull detection, dangerous capability combinations.

Input Validation 9 checks

SSRF via tool parameters, cloud metadata endpoint access, command injection, SQL injection, path traversal, URL scheme validation.

Data Security 6 checks

Credential patterns in schemas, PII exposure, secrets in error messages, sensitive data in URL parameters, cross-server data leakage.

Supply Chain 8 checks

npm provenance verification, known CVE matching, typosquat detection, maintainer reputation, source repo verification, abandonment detection.

Infrastructure 8 checks

Network binding audit, TLS enforcement, rate limiting, CORS configuration, error handling, security headers, DNS rebinding protection.

Runtime Behavior 5 checks

Guardrail bypass patterns, response size limits, timeout enforcement, and concurrency safety signals that feed buyer confidence and deeper review.

A2A Agent Cards 5 checks

Google A2A Agent Card security: prompt injection in descriptions, obfuscated content, identity spoofing, HTTPS enforcement, capability over-privilege.

Fairness & Bias 3 checks

Demographic signal detection in tool parameters, differential treatment risk assessment, and data governance gap analysis. Maps to EU AI Act Article 10.