gateway — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gateway (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Governance from Day 1. A security-hardened, governance-first autonomous AI agent platform.
ISG Agent 1 proves that autonomous AI agents can be both powerful and safe. While other agent platforms bolt on security as an afterthought, ISG Agent 1 bakes governance into every layer from the start.
| Innovation | What It Does |
|---|---|
| Agent Constitution | Machine-enforced behavioral contract -- not guidelines, a verified contract |
| Adversarial Self-Testing | The agent red-teams itself in production on a schedule |
| Time-Locked Actions | Mandatory cooling period before dangerous operations (30-60s) |
| Trust Ledger | Transparent, cryptographic reputation tracking for every action |
| Explain Mode | Cryptographic proof of why every decision was made |
| Skill Reputation | Community-verified trust scores for agent skills |
| Separation of Powers | Critical actions require approval from independent agent or human |
ISG Agent 1 was built as a direct response to the security failures in existing agent platforms. Where others have exposed instances, malicious skills, and no audit trails, ISG Agent 1 has localhost-only defaults, skill quarantine, and hash-chained audit logs.
git clone https://github.com/InnovativeSystemsGlobal/isg-agent-1.git
cd isg-agent-1
cd gateway
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp ../.env.example ../.env
cp ../config/agent.example.yaml ../config/agent.yaml
python -m isg_agentThe gateway starts on http://localhost:8900 by default (localhost-only).
User (Discord/Telegram/Web)
-> Bridge (TypeScript, normalizes messages)
-> Gateway (Python/FastAPI, governance engine)
-> Constitution check
-> Governance gate (PROCEED/REVIEW/HALT)
-> Audit trail (SHA-256 hash chain)
-> Brain (LLM + convergence guarantees)
-> Skills (sandboxed, quarantined, reputation-scored)
-> Response (governed, explained, audited)See ARCHITECTURE.md for the full architecture overview.
See CONTRIBUTING.md for contribution guidelines.
See SECURITY.md for our responsible disclosure policy.
MIT License. See LICENSE for details.
Innovative Systems Global. The name is not aspirational. It is a statement of fact.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.