Insygna offers a free report card that grades agents before they get access
The free service tests an agent's repository across six security dimensions and issues a Verified badge before credentials are granted. Early results argue most agents should not be hired yet.
Insygna launched a free public service on Tuesday that grades AI agents before they touch production systems. The Agent Report Card lets any company connect an agent's repository, run independent tests, and get back a security score out of 100, a detailed findings list, and, for agents that clear the bar, an Insygna Verified badge meant to travel with the agent wherever it is deployed.
The score is weighted across six dimensions, according to AIThority's coverage: secret exposure, dependency vulnerabilities, code security, container hardening, LLM security measured against the OWASP LLM Top 10, and image security. Findings are spelled out to the file, the line, and the fix, and every agent keeps a version history, so a risk team can require a fresh report card on each release the way it requires a penetration test on each product launch. The service ties into Insygna's Agentic Workforce Management platform, which assigns agents a verifiable identity and a managed lifecycle across Microsoft Teams, Slack, Copilot, Claude, and ChatGPT, plus agents built on Oracle, Salesforce, Workday, and ServiceNow.
The numbers behind the pitch
Insygna's early data explains why it is giving the scoring away. The median agent the company has tested scores below 50 out of 100, and roughly six in ten land in that failing range, per figures reported by AIThority. That tracks with independent research: a June AI Risk Quadrant assessment of 100 commercial agents found only 11 percent met an acceptable security bar, Help Net Security reported, with 98 percent combining private data access, untrusted content exposure, and outbound action in one package. Gartner projections cited in the launch coverage put the average Fortune 500 company at roughly 150,000 agents by 2028, against about 15 in 2025, while only 13 percent of organizations say they have adequate controls today. The launch was flagged in this week's agent industry roundups alongside a wave of similar governance releases.
Who gets to certify the workforce
For the protocols beat, the product itself matters less than the position it stakes out. The agent economy has been converging on identity rails, with Okta's agent identity rollout and the ITU's standards work defining who an agent is. A report card answers the next question: whether that identified agent is safe to employ. Attach a score and a badge to an identity, and procurement suddenly has a document to demand, the same shift verified MCP server programs brought to the tool-server side of the stack.
The obvious caveat is that Insygna is grading the market it sells into, and a free scan is a lead-generation funnel as much as a public service. A vendor-issued badge is not a standard, and the ecosystem should expect competing scorecards until a neutral body claims the role. But the mechanics are directionally right. GaaS buyers already ask what a rented agent can do. The report card era makes them ask what it scored, and agents that arrive without a number will start to look like candidates without references.