CoreDhristi
Hire a DevHost Your AgentBid for RequirementsPricingAbout
Sign inSign Up
Back to Blog
SecurityOWASPTrust & Safety

AI Security & OWASP Top 10: How CoreDhristi Scans and Protects Private Code

CoreDhristi Team·25 Jun 2026·9 min read

Every piece of software carries risk, and AI agents carry a specific kind: they are often granted broader access than a typical script, to files, APIs, credentials, and sometimes to other internal systems, because that access is what lets them act autonomously in the first place. A marketplace that lets anyone list an agent without checking what that agent actually does is, in effect, asking companies to grant broad system access to code they have never reviewed. CoreDhristi's security review exists to close that gap before an agent ever reaches a company's environment.

The review runs in seven layers, and each layer catches a different class of problem. The first layer is secret scanning with Betterleaks. This step exists for a narrower but very common problem: developers accidentally committing API keys, database credentials, or private tokens directly into their source code. It happens more often than most people expect, and when it happens in a package that gets installed by many different companies, a single leaked credential can turn into a much larger incident. Betterleaks scans the full history of what is being submitted, not just the current state of the files, to catch secrets that may have been added and later removed but never actually rotated.

The second layer is static analysis with Semgrep and CodeQL, which scan the submitted code for patterns associated with the OWASP Top 10, the industry-standard list of the most critical web application security risks: injection flaws, broken access control, insecure deserialization, and similar categories. Static analysis does not execute the code. It reads it, the same way a careful human reviewer would, looking for the shapes of code that historically correlate with exploitable bugs.

The third layer is a dependency and supply-chain scan, using OSV-Scanner across JavaScript, TypeScript, Python and more, which checks every third-party library the agent depends on against known vulnerability databases. Modern software rarely fails because of code the developer wrote themselves. It fails because of a vulnerable dependency three or four levels deep in the dependency tree that nobody was watching. This layer surfaces those known CVEs before the agent is listed, rather than after a company has already deployed it.

The fourth layer is an automated QA and functionality check. The scan installs the agent the same way a buyer would, runs its build step, and executes the agent's own test suite in a sandboxed runner. An agent that does not install cleanly or does not build never reaches the marketplace, and failing tests block the listing. Security scanning tells you code is not dangerous; this layer tells you it actually works.

The fifth layer is automated attack simulation with Promptfoo, which runs simulated adversarial attacks across dozens of vulnerability categories to see how the agent behaves under hostile input rather than only under the happy path. The sixth layer verifies what an agent actually does rather than what it claims: Agentic Radar traces the real structure of an n8n or framework-based automation, and MCP Inspector connects to an MCP server and lists the tools it genuinely exposes, each running on the listing types it applies to. The seventh layer checks the developer's data claims with Presidio and publishes a full software bill of materials with Syft, so a buyer can see the personal-data handling and the exact dependency set they are taking on. Those last two layers catch design and supply-chain decisions no code scanner sees on its own.

None of these layers replaces the others, and each one catches a class of problem the rest would miss. The review is fully automated end to end, with no human-review step, so it runs the same way on the first listing as on the ten-thousandth and does not slow down as the marketplace grows. That is what "Verified" is meant to signal: not that an agent is perfect, no review process can promise that, but that it has been checked against real, industry-recognized standards before a company ever runs it. If you are a developer preparing your own listing for this review, here is how the rest of the listing process works, from pricing to payout.

Back to Blog
CoreDhristi

The marketplace for secure, vetted AI agents, custom MCP servers, AI automations, and verified agent developers.

Platform

MarketplaceHire a DeveloperFree SkillsPricing PlansAbout Us

Resources

DocumentationBlogCustomer HelpContact UsJoin our Discord Community

Legal

Privacy PolicyTerms & ConditionsTrust & IP Protection
Secure Vetted Sandbox

Every agent runs a fully-automated 7-layer review (Betterleaks, Semgrep, CodeQL, OSV-Scanner, QA, Promptfoo, Agentic Radar, MCP Inspector, Presidio, Syft) before publishing.

© 2026 CoreDhristi. All rights reserved.
Global billing active (INR / USD supported)