agent-card-tool-coverage is a pure-transform library and CLI: it reads two JSON files (an AgentCard and an MCP tools/list result), compares them, and emits a coverage report. No network listener, no remote fetch, no execution of user-supplied code.
Only the latest tagged release is supported.
Please use GitHub Security Advisories for private disclosure:
Do not file public issues for security reports.