Sato Check
Check before you install
Sato Check reads what an agent's code can do with its keys and money — before it is installed, and every time it changes.
- 1Does it take your key?
- 2Does your key leave?
- 3Can it move funds on its own?
- 4What changed?
How it works
Every line of evidence carries exactly one class, and each answer shows the strongest class behind it.
- declared
- The project says so — README, config, env list or tool description.
- traced
- Our static read of the published artifact found it.
- observed
- We ran it with planted test keys and saw it.
What it does not claim
A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".
"Unknown" means we could not look, not that something is wrong. A planted key observed leaving is the one fact a profile states as fact, with the host it went to.