There are more AI agents shipping every week than any security team can review by hand. Coding agents, browser agents, Web3 trading bots, MCP servers, installable skills, voice assistants. Each one can read your data, call your tools, and act on your behalf. Almost none of them arrive with a security label.
AgentReady's Agent Listing from Distributedapps.ai is an attempt to put a label on the whole field. It holds 4,570 AI agents, and every single one carries a security readiness score measured against the agentic frameworks that actually matter: CSA MAESTRO, and OWASP AIVSS. Browse it for two minutes and a pattern jumps out. Popular, free, widely installed agents routinely score 9.5 out of 10 on AIVSS, which is the Critical band. The score is based on public information available online. If we have more insights on the agent or the provider, and the agent providers submit more information, the score can be adjusted. As such, the score is just a reference at this point.
Those scores come from AgentReady, a platform built by DistributedApps.ai over the past year and now available as a beta version at distributedapps.ai/agent-listing. AgentReady ships two documents that anyone on a paid AgentReady plan downloads for free: the Agentic AI Security Controls Framework (176 controls across eight domains, each with a standards citation) and the Agentic AI Readiness Assessment Questionnaire (five readiness dimensions scored one to five, from Initial to Optimizing). To get both, sign up for any paid plan there.
Here is how I will spend the rest of this post. The free half explains what the score means, where it comes from, and why a directory of scored agents is more useful than another threat-model blog post. It stands on its own. The paid half is a runbook: how to take the same two documents everyone on a paid AgentReady plan gets for free, the Security Controls Framework and the Readiness Assessment Questionnaire, and run your first real readiness assessment on your own agent this week. Anyone on a paid AgentReady plan gets both of these important documents for free, the moment they are on a plan.
Traditional application security assumes software does what its code says. Agentic AI breaks that assumption. An agent reads a webpage, a document, or a tool response, and that text can rewrite its goals mid-task. The moment an agent has delegated authority and a set of tools, the untrusted input it reads becomes a control channel.
Figure 1 shows why the usual perimeter thinking fails here. The agent sits in the middle holding real authority, and the threats do not come through one front door. Indirect prompt injection rides in on content the agent was told to read. Tools and MCP servers can be poisoned at the source. Other agents can impersonate trusted peers. The model or an installed skill can be compromised in the supply chain. And once any of those lands, insecure tool use turns a single compromise into lateral movement and data exfiltration. Every arrow points inward, and none of them is a network port you can close.
Figure 1: The Agentic Attack Surface
This is the gap the frameworks were built to close, and it is the gap a scored directory makes visible. You cannot fix what you cannot see, and until recently the security posture of an agent was invisible until after it misbehaved.
Agent Listing is a catalog of 4,570 agents, each one placed in a category and each one scored based on available public information. The categories alone tell you where the risk is concentrated: 533 MCP tools and agents, 361 agent platforms, 309 agent skills, 289 agent plugins, 204 agent frameworks, and long tails for voice, video, coding, sales, and customer service. These are not toys. MCP tools and installable skills are exactly the surfaces that get poisoned, and they are the two largest buckets in the directory.
Figure 2 shows the pipeline behind each listing. An agent or MCP tool goes in. It is assessed against both frameworks together, not one in isolation. That assessment produces an AIVSS score on a zero to ten scale, and that number lands in a severity band: Critical, High, or Medium. The score is the compression of a lot of structured analysis into a single comparable number, which is the only reason you can scan 4,570 agents at once.
Figure 2: How Agent Listing Scores An Agent
The reason the score is credible is that it is not one person's opinion. It combines two independent frameworks, each looking at the same agent from a different angle.
Figure 3 lays out the two lenses. CSA MAESTRO answers "where can it go wrong," modeling threats layer by layer from the foundation model up through the deployment and the agent ecosystem. OWASP AIVSS answers "how bad is it," turning that analysis into a comparable score the way CVSS did for classic vulnerabilities. One lens on its own is easy to game. Two independent lenses pointing at the same agent are much harder to argue with, and their combined output is the readiness score you see on every card.
Figure 3: Two Lenses, One Score
Grounding the score in named, active frameworks is what separates this from a vibe check. Every judgment traces back to a specific, published standard rather than a reviewer's gut feeling, which means you can defend the number to an auditor or a skeptical engineering lead.
A score tells you that you have a problem. It does not tell you what to do on Monday. That is the job AgentReady does around the listing, and it is why the two are worth talking about together.
Figure 4 shows the path. You start with a free check, which produces a report of findings and gaps for a specific agent or system. The report hands you the two included documents, the Security Controls Framework and the Readiness Assessment Questionnaire, which turn findings into concrete remediation and a readiness baseline. From there, a plan, Team, Pro, or Enterprise, gives you the monitoring, the corpus, and the per-finding citations to actually close the gaps and keep them closed. The score starts the conversation, and the documents plus the plan finish it.
Figure 4: The AgentReady Flow
The important design choice is that every paid AgentReady plan includes both documents for free. They are not a separate upsell. The moment you are on a plan, you download both, because the whole point is to get the framework and the questionnaire into your team's hands, not to nickel and dime the thing that makes the score actionable.
AgentReady is the platform behind these scores. Browse the full Agent Listing there, run a security check on your own agent, and on any paid plan download both documents for free.
The first guide is the Agentic AI Security Controls Framework, version 3.0. It carries 176 granular controls, expanded from 125 in the prior edition after a full research pass against the 2025 to 2026 threat landscape. Every control carries a Standards Alignment citation that grounds it in a currently active framework or a disclosed incident, so no control is there because someone felt like it.
Figure 5 shows how those 176 controls are organized. Eight domains cover the full lifecycle of an agentic system: Authentication and Access Control, Data Protection and Privacy, Model Integrity and Governance, Secure Agentic Interaction and Tool Use, Multi-Agent Coordination Security, Secure Development and Deployment, Monitoring, Logging, and Incident Response, and Resilience and Business Continuity. The structure matters because it maps cleanly onto the attack surface in Figure 1. Tool poisoning and prompt injection live under Secure Agentic Interaction and Tool Use. A2A impersonation lives under Multi-Agent Coordination Security. Each threat you can name has a home, and each home has controls.
Figure 5: Eight Control Domains, 176 Controls
The second guide is the Agentic AI Readiness Assessment Questionnaire, version 3.0. It is aimed at Chief AI Officers, senior executives, and implementation teams, and it measures organizational readiness across five dimensions: Strategic Alignment, Technical Infrastructure, Governance and Risk Management, Organizational Capabilities, and Implementation Maturity. You score each question from one to five based on your current state, not your aspirations, and the dimension scores roll up into an overall maturity level.
Table 1 shows how those overall scores translate into a maturity verdict and a decision. The reason this matters is that a single number, say a 2.4, is meaningless until it tells you what you are allowed to do next. The bands turn the score into a gate: below 2.0 you are still doing foundational work, in the 2.0 to 2.9 Defined band you can run pilots while you build capability, the 3.0 to 3.9 Managed band clears you for scaled rollout, and 4.0 and up means you are ready for advanced agentic deployments. It is the difference between "we scored a 2.4" and "we are cleared for pilots but not production."
Table 1: Readiness Maturity Levels
Together the two guides answer the two questions every team stuck on agentic AI is actually asking. The framework answers "which specific controls do I need," and the questionnaire answers "am I organizationally ready to run them." One is technical depth, the other is executive readiness, and you need both to move an agent from a demo to production without a security incident writing your roadmap for you.
If you stop reading here, you have enough to be useful. You know what the AIVSS score means and why a 9.5 is not marketing hyperbole. You know the two frameworks behind it and why combining them makes the number credible. You know the eight control domains and the five readiness dimensions, and you know anyone on a paid AgentReady plan gets both documents for free.
You do not have to wait for the paywall to get the documents. Sign up for any paid AgentReady plan on the website at distributedapps.ai/agent-listing, and both guides are yours to download for free the moment you are on a plan. If you want them, sign up on the AgentReady site, not here.
The paid half is the part that turns all of that into a scheduled, repeatable process. Below, I walk through running your first readiness assessment this week: how to staff it, how to score it honestly, how to map your lowest-scoring gaps onto specific controls from the 176, and how to turn the whole thing into a loop instead of a one-time slide deck. If your job is to get an agent to production without becoming a case study, this is the operational part.
For this newsletter's paid subscribers, the hands-on runbook continues below.
Everything above is free: what the AIVSS score means, the brief introduction of the two frameworks, the eight control domains, and the five readiness dimensions. The section below is for this newsletter's paid subscribers. It walks through running your first readiness assessment this week, how to staff it, how to score current state honestly, how to map your lowest scores to specific controls from the 176, and how to turn the assessment into a quarterly loop.