Risk OS Red Try Stoa
Stoa · Agent Risk Scanner

Every agent inventoried.
Every claim evidenced.

A local-first static scanner that finds likely AI agents in Python, JavaScript, and TypeScript, maps what they can reach, scores them across eight risk dimensions, and blocks newly introduced high-confidence critical risks — without uploading a line of code. Every finding is anchored to the OWASP LLM Top 10 and the EU AI Act, and a scan can pre-fill an insurer’s risk questionnaire from evidence.

$ pipx install stoa-agent-risk
$ stoa scan .  &&  open stoa-report.html
Local-firstZero telemetryNo accountsPython 3.10+MIT