Model or dataset
ZhangJinHaHaHa/AgentLens avatar
ZhangJinHaHaHa/AgentLens

A bare IP homepage, a quick start that cd's into itself, and an R4 tier nobody can rent yet

Agentlens is a trusted agent trading platform. Here, you can quickly find the Agent that meets your needs, and you can also publish your own Agent to turn it into your digital asset. We encourage everyone to transform their areas of expertise into Agents and turn them into digital assets, allowing others to see your unique strengths.

1,028 stars60 forksTypeScriptAGPL-3.0

At a glance

What is it?
AgentLens is an AGPL-3.0 repository for a marketplace where people rent AI agents under Solidity contracts rather than buy them, published as a sanitized copy that deliberately omits the routing, scoring and billing logic. What you can read is a protocol surface and a set of runtime tiers, not the system that runs them.
Who is it for?
It fits protocol reviewers, integrators and sellers who need the contract schemas, the R0 to R4 semantics and the credential boundary rules, and it does not fit anyone trying to evaluate the platform itself, since the routing, quality scoring and billing stay private and the declared homepage is a bare address.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 39 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The declared homepage is a bare address over plain HTTP

The homepage recorded on the repository is http://203.91.76.159/, a numeric address with no hostname and no TLS. The README links somewhere else entirely, sending readers to https://agentlens.chat/en as the live platform, alongside a public protocols index, an integration guide, a security policy and a Chinese README. So there are two destinations in play and the one recorded on the repository is the one with no name attached to it. That is worth knowing before you type anything into either. An address with no certificate and no domain tells you nothing about who operates it or what it serves, while the README's own framing is that hosted Brain strategies, production routing, credential handling and deployment automation are all private, which means a local clone and the live site are different products by design.

The quick start leaves you inside frontend, then tells you to change into it

The install block walks three directories in sequence and ends inside the third:

bash
git clone https://github.com/ZhangJinHaHaHa/AgentLens.git
cd AgentLens

cd contracts && npm install && npm test
cd ../sandbox && npm install && npm test
cd ../frontend && npm install && npm test && npm run build

The very next section, for running the frontend locally, opens with `cd frontend` again. Following the document in order leaves you in frontend/ with nothing left to change into, so the last two commands fail on a fresh clone. The requirement list above them also names Docker for container audit exercises, while the tree has contracts/, sandbox/, frontend/, docs/, scripts/ and no Dockerfile and no compose file, so that path has nothing in the repository to build. Requirements are Node.js 20+ and npm 10+. The install flow itself is otherwise honest about its limits, stating that features needing a hosted provider, an authenticated seller account or a managed runtime stay unavailable in a standalone clone.

The architecture diagram ends without closing its own string

The mermaid flowchart in the README has eleven edges and the last one is unfinished:

mermaid
    Audit["Sandbox, Attestation and ZK Adapters"] --> Chain["Public Smart Contracts"

There is no closing quote and no closing bracket on the chain node, so the diagram does not parse as printed, and the node it was meant to point at has no name. The surrounding text is careful about what the diagram claims, saying it describes public trust boundaries rather than the production network topology, but the block itself is broken in the one place where the audit path is drawn. The Repository Boundary table that would close the README is cut off mid-row as well, ending at a partial entry for the non-sensitive sandbox and verification code, so the two sections meant to define exactly what is public and what is not are the two that do not finish.

This repository is the sanitized half of the product

The README states plainly that it is the sanitized public source distribution, containing the public product surface, contracts, integration schemas and non-sensitive audit reference code. What stays in the hosted private service is a longer list: Brain strategies, production routing, Workers, capability-broker policy, quality scoring, billing ledgers, credentials, topology and deployment automation. The boundary table repeats the split from the other direction, pairing the public frontend and catalog against the workspace control plane, smart contracts and ABIs against production addresses, signers and chain operations, and protocol schemas and OpenAPI against Brain prompts, routing algorithms and Provider weights. The honest reading is that the trust system is public and the thing being trusted is not, so you can audit the interface of the platform without seeing how it decides anything.

Renting is time-limited, so the digital asset framing does not survive

The repository description pitches publishing your own Agent to turn it into a digital asset, letting others see your strengths. The README draws the boundary differently: AgentLens provides the brain and governed runtime, sellers provide the specialized Agent, and renting one grants time-limited execution access that does not transfer source code or permanent ownership. The smart contracts match the README rather than the description, being rental-only and covering time-limited access, reviews, audit records, appeals and reputation primitives. So there is no transfer of the thing being sold. What a seller actually publishes is either a code artifact or an API endpoint, and what the buyer gets is a window. Rental accounting is one of the topics the protocol index covers alongside versioning, credential boundaries and R0-R4 semantics.

A listing can be a remote API carrying no source audit

Sellers get two paths, and the README is explicit that they make different claims. One submits a code artifact for platform processing, the other registers a seller-hosted HTTPS API. API-only listings never inherit source-audit claims, which means a marketplace entry can point at a remote endpoint that nobody on the platform has read. The same caution is repeated on the inspection side, where agent detail pages are said to distinguish platform-native audited execution from seller-hosted APIs and from external handoff, and the line drawn is that a recognized listing is not automatically a sandbox guarantee. The catalog itself splits runnable marketplace Agents from external AI tool guidance, so a search result is not a promise that you can execute anything. Structured fields are said to describe scenario fit, execution mode, risk, evidence and recommended next steps.

R4 exists in the schema and is deferred in the availability column

Five runtime planes are defined, each with a plane name and an availability statement. R0 is `sealed_ephemeral` for isolated short-lived file and artifact tasks, at base contract. R1 is `brokered_egress` for governed HTTP, search and connector access, permission and budget controlled. R2 is `durable_session` with checkpoints, resume, persistent volumes and long jobs, lifecycle metered. R3 is `browser_computer` for read-only or interactive browser sessions, separately isolated and approved. R4 is `accelerated_external` for GPU, special OS and very large storage, and its availability statement is the only one that declines to commit: reserved, with extreme workloads currently deferred. The accompanying rule is the one that matters most, since a schema can describe a capability without promising any deployment supplies it, and an Agent must pass runtime conformance before listing, with unsupported capabilities failing closed rather than silently degrading.

The security section spends its length on what evidence cannot prove

The most specific prose in the repository is the part explaining what its own records are worth. Platform and seller credentials must stay server side and must never appear in Wire frames, browser bundles, traces or artifacts. Submitted endpoints and network calls require SSRF-resistant validation, resolved-address checks, timeouts, response limits and authorization. Audit evidence is bound to versions and content hashes, and optional TEE or ZK adapters can strengthen a record, but their presence must be verified per record and must not be inferred from a generic listing. Historical or mock attestations are explicitly not production hardware claims, and seller QA is called input evidence rather than proof of marketplace quality, with platform quality records required to identify both the target artifact and the runtime version. Vulnerabilities are asked for privately through SECURITY.md, with no exploit details published before a fix exists.

Editorial conclusion

It fits protocol reviewers, integrators and sellers who need the contract schemas, the R0 to R4 semantics and the credential boundary rules, and it does not fit anyone trying to evaluate the platform itself, since the routing, quality scoring and billing stay private and the declared homepage is a bare address. Before reading anything into a listing, check whether it came from the seller-hosted API path or the artifact path, because only one of them carries source-audit claims. Treat attestation and ZK fields as unverified until checked per record, expect R4 work to be unavailable, and remember the install walkthrough leaves you inside the frontend directory before it tells you to change into it.

Frequently asked questions

What does AgentLens actually sell?

Rented access, not ownership. Renting an Agent grants time-limited execution access and does not transfer source code or permanent ownership, while the smart contracts cover time-limited access, reviews, audit records, appeals and reputation primitives.

What are the R0 to R4 runtime planes in AgentLens?

R0 sealed_ephemeral, R1 brokered_egress, R2 durable_session, R3 browser_computer and R4 accelerated_external. R4 is marked reserved with extreme workloads currently deferred, and an Agent must pass runtime conformance before it can be listed.

Does an AgentLens listing guarantee the agent was audited?

No. Sellers can either submit a code artifact for platform processing or register a seller-hosted HTTPS API, and API-only listings never inherit source-audit claims. A recognized listing is not automatically a sandbox guarantee.

What is not included in the AgentLens repository?

Hosted Brain strategies, production routing, Workers, capability-broker policy, quality scoring, billing ledgers, credentials, topology and deployment automation. The repository describes itself as the sanitized public source distribution.

What does it take to run the AgentLens frontend locally?

Node.js 20+ and npm 10+, then install and test in contracts, sandbox and frontend. Docker is listed only for container audit exercises, and features needing a hosted provider, a seller account or a managed runtime stay unavailable in a clone.

Official sources

  1. Issues
  2. License: AGPL-3.0
  3. Project website
  4. README
  5. ZhangJinHaHaHa/AgentLens on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/zhangjinhahaha-agentlens.svg)](https://hysenlabs.com/projects/zhangjinhahaha-agentlens)