286 dependencies found in AutoGPT
An agent platform rather than a library or a service — a Python backend, a TypeScript frontend, and a catalogue of shipped agent graphs. It is here because it locks its dependencies with poetry rather than uv, which until this week made its entire dependency tree invisible to lading.
- Repository
- Significant-Gravitas/AutoGPT
- Commit
- 98381ab27f733468bfe1f9c4f4942b4b416d9a8b
- Subject
- hotfix(frontend/marketplace): show a Coming soon label on expert pages instead of hire actions
- Scanned
- 2026-09-16 · 2,877 source files
This is an independent analysis of a public repository. Foretop is not affiliated with or endorsed by the repository owner.
What Ebb, telltale, charter and lading found
Ebb, telltale, charter and lading are the checks you can install and re-run yourself today. Each one's scope, its result, and — below — every source it matched.
| Check | Scope | Results | Outcome |
|---|---|---|---|
| ebb | whole repo | 2,195 | Model IDs matched against the bundled retirement registry. |
| telltale | autogpt_platform/frontend/src/app/api/openapi.json | 4,076 | 348 documented operations checked against every Prometheus alert rule, OTel Collector pipeline and Grafana dashboard committed to this repo, and against any HTTP auto-instrumentation registered in its own code. |
| charter | repo root | — | No .mcp.json or .cursor/mcp.json in the repo — no agent configuration is declared here, so there is nothing to hold a capability baseline against. |
| lading | autogpt_platform/backend | 569 | 286 packages from the real poetry.lock, 190 resolved to a licence, each classified direct or transitive and production or development from the lockfile's own dependency graph — poetry's `[tool.poetry.group]` roots included. Scoped to one sub-package: AutoGPT has no root lockfile, and three live under autogpt_platform/ and classic/. |
Every result, grouped and filterable
Deduplicated into real issue groups, never one row per raw occurrence. Filter by check, deadline, provider or context, or search — every filter is reflected in the URL, so a filtered view is a link you can share.
No telemetry configuration (Prometheus alert rules, an OTel Collector config, or a Grafana dashboard) was found anywhere in this repository. This does not prove the hosted service is unmonitored — only that none is declared here.
1 issue group across 38 occurrences · 6,557 scanned
Act now claude-sonnet-4-20250514 Act now · retired 2026-06-15 · configuration reference 38 occurrence(s)
And the 629 we could not answer
629 of ebb's 2,195 results are ?unknown — model strings that are real references but are not in the retirement registry, so no deadline can be claimed for them. They are reported as unknown, not quietly dropped and not counted as clear. They are visible in the Review tab above, not hidden below the fold.
If a tool showed you only the 1,566 it could resolve and said nothing about the other 629 strings it walked past, you would have no way to know the difference between "checked and fine" and "never looked".
The same five checks, elsewhere
What a suite is for: the answers come back in a different shape for every codebase, and which checks have nothing to say is itself information.
LangChain — 1 model migration found in LangChain · Langfuse — 117 API operations with no declared telemetry config found in Langfuse · nuxt.com — 3 declared MCP servers found in nuxt.com · the CZI data portal — 4 MCP servers with elevated access found in the CZI data portal
Preview: what Undertow observed
Undertow is still in development. It is not publicly installable, and nothing below can be reproduced by a reader today — it is shown because a check that cannot see something has to say so, including here. Ebb, telltale, charter and lading, above, are all available now.
| Check | Scope | Observations | Outcome |
|---|---|---|---|
| undertow | — | — | Scans vendor subprocessor pages by URL, not repositories. Nothing in a source tree is in its scope by design. |
Run it on yours
Same command, same registry, no account and no upload — detection is local and only results ever leave your machine.
Results above are a snapshot at
commit 98381ab, taken 2026-09-16. Both
projects move quickly; re-running it today may return something different, which is
rather the point.