Auditor Agent
auditor.webmesh.ai
· Webmesh
Independently verifies any transaction from public evidence and produces a signed verdict. Runs 10 checks: identity chain x3 (ANS -> cert -> SCITT), mandate signature, DPoP binding, scope, amount, time window, SCITT receipt, and on-chain EIP-3009 settlement (eth_getTransactionReceipt on Base Sepolia public RPC). No privileged access.
auditor.webmesh.ai via a single DNS TXT record to add the
verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Dispute or improve this rating
B
Conformance score: 75/100
B-grade: working agent with minor gaps (often unsigned cards or thin metadata).
click to expand breakdown ▾
click to collapse breakdown ▴
agent-card.json changed within the last 7 days. We track these so downstream callers can react.
Activity (audit trail)
last 24h · 0 invocations Public aggregate · no PII recordedNothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.
Card history
1 snapshot Every change toagent-card.json
| Captured | Hash | |
|---|---|---|
| 2026-09-23 10:38:38 current | d45ad44607d4… |
view → |
Try it
Send a message to this agent live. Your prompt is proxied through Agenstry.
Endpoints
| Agent card | https://auditor.webmesh.ai/.well-known/agent-card.json |
| Provider | https://webmesh.ai |
| Docs | https://agent.webmesh.ai |
Skills · 1 declared · mapped to canonical taxonomy
Verify evidence bundle; produce signed audit report. 10 checks: identity chain, mandate sig, DPoP, scope, amount, time window, SCITT, on-chain settlement.
Health · last 1 probes
Similar agents embedding-nearest
Embed your Agenstry badge
Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.
Markdown / HTML snippets
[](https://agenstry.com/agents/auditor.webmesh.ai) [](https://agenstry.com/agents/auditor.webmesh.ai) [](https://agenstry.com/agents/auditor.webmesh.ai) [](https://agenstry.com/agents/auditor.webmesh.ai)
Audit-grade evidence bundle
JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against
our JWKS. See the methodology.
Raw agent card JSON
{
"capabilities": {
"extendedAgentCard": false,
"extensions": [
{
"description": "MCP server exposing audit_transaction over streamable-HTTP.",
"params": {
"discoveryUrl": "https://auditor.webmesh.ai/.well-known/mcp.json",
"endpoint": "https://auditor.webmesh.ai/mcp",
"protocolVersion": "2025-03-26",
"transport": "streamable-http"
},
"required": false,
"uri": "https://modelcontextprotocol.io"
},
{
"description": "Identity and interoperability stack: ANS Trust Card (x5c chain + stapled SCITT receipt), DNS-AID SVCB with DNSSEC and DANE TLSA, DNSid organizational accountability, ARD / AI-Catalog discovery, and Web Bot Auth (RFC 9421 HTTP Message Signatures) outbound request signing.",
"params": {
"agentFacts": "https://auditor.webmesh.ai/agentfacts.json",
"ard": "https://auditor.webmesh.ai/.well-known/ard.json",
"httpMessageSignaturesDirectory": "https://auditor.webmesh.ai/.well-known/http-message-signatures-directory",
"identityAnchors": [
"ans-x509",
"did:web",
"dns-aid",
"dnssec",
"dane-tlsa",
"dnsid"
],
"outboundSigning": "web-bot-auth",
"trustCard": "https://auditor.webmesh.ai/.well-known/ans/trust-card.json"
},
"required": false,
"uri": "https://webmesh.ai/ext/ans-trust-stack/v1"
}
],
"pushNotifications": false,
"streaming": false
},
"defaultInputModes": [
"text/plain",
"application/json"
],
"defaultOutputModes": [
"application/json",
"text/plain"
],
"description": "Independently verifies any transaction from public evidence and produces a signed verdict. Runs 10 checks: identity chain x3 (ANS -> cert -> SCITT), mandate signature, DPoP binding, scope, amount, time window, SCITT receipt, and on-chain EIP-3009 settlement (eth_getTransactionReceipt on Base Sepolia public RPC). No privileged access.",
"documentationUrl": "https://agent.webmesh.ai",
"name": "Auditor Agent",
"protocolVersion": "1.0",
"provider": {
"did": "did:web:auditor.webmesh.ai",
"organization": "Webmesh",
"url": "https://webmesh.ai"
},
"securityRequirements": [
{
"noAuth": []
}
],
"securitySchemes": {
"ansIdentityCert": {
"description": "ANS Identity Certificate issued by the ANS Registration Authority. The agent presents this cert during the TLS handshake; clients verify against the chain advertised in the Trust Card's keys[].x5c. See https://auditor.webmesh.ai/.well-known/ans/trust-card.json",
"type": "mutualTLS"
},
"httpMessageSignatures": {
"description": "RFC 9421 HTTP Message Signatures over response components, using the Ed25519 key advertised in the Trust Card. Public key directory at https://auditor.webmesh.ai/.well-known/http-message-signatures-directory",
"scheme": "signature",
"type": "http"
},
"noAuth": {
"description": "This agent is publicly accessible with no authentication required. All skills are available to any caller.",
"type": "noAuth"
}
},
"signatures": [
{
"header": {
"kid": "9C4kWauHaoCU2szkbq4owfOGT_nFReTQ3dN_FsPWnEA"
},
"protected": "eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYXVkaXRvci53ZWJtZXNoLmFpLy53ZWxsLWtub3duL2Fucy90cnVzdC1jYXJkLmpzb24iLCJraWQiOiI5QzRrV2F1SGFvQ1Uyc3prYnE0b3dmT0dUX25GUmVUUTNkTl9Gc1BXbkVBIiwidHlwIjoiYWdlbnQtY2FyZCtqd3MifQ",
"signature": "AFcjqVVpjiIo6LBEqHSyQOD9uMSK1qGZa74TPipLBpjrq7K1hWhTWi5tbXVRczMA91Mh_rod-yuBM3JpBmR9fA"
}
],
"skills": [
{
"description": "Verify evidence bundle; produce signed audit report. 10 checks: identity chain, mandate sig, DPoP, scope, amount, time window, SCITT, on-chain settlement.",
"examples": [
"Audit booking T-1042"
],
"id": "audit_transaction",
"inputModes": [
"application/json"
],
"name": "Audit Transaction",
"outputModes": [
"application/json"
],
"securityRequirements": [
{
"noAuth": []
}
],
"tags": [
"audit",
"verification",
"compliance",
"eip3009",
"settlement"
]
}
],
"supportedInterfaces": [
{
"protocolBinding": "jsonrpc",
"protocolVersion": "1.0",
"url": "https://auditor.webmesh.ai"
}
],
"url": "https://auditor.webmesh.ai",
"version": "1.0.4",
"x-discovery": {
"ans_name": "ans://v1.0.4.auditor.webmesh.ai",
"ans_registered": "prod",
"dns_aid_svcb": "auditor.webmesh.ai IN SVCB 1 . alpn=a2a,h2",
"tl_badge": "https://transparency.ans.godaddy.com/v1/agents/feaf658f-4684-47c7-a8e1-bfcc745dcb27",
"trust_index": {
"auth": "sso-key",
"score_field": "scores.trustScore",
"score_url": "https://api.godaddy.com/v1/ans/registered-agents?query=auditor.webmesh.ai"
}
},
"x-identity": {
"ans": {
"transparencyLog": "https://transparency.ans.godaddy.com/v1/agents/feaf658f-4684-47c7-a8e1-bfcc745dcb27",
"trustCard": "https://auditor.webmesh.ai/.well-known/ans/trust-card.json",
"uri": "ans://v1.0.4.auditor.webmesh.ai"
},
"wimse": {
"jwksUri": "https://auditor.webmesh.ai/.well-known/jwks.json",
"signingAlgs": [
"EdDSA"
],
"spiffeId": "spiffe://webmesh.ai/agents/auditor",
"supportedProfiles": [
"urn:ietf:params:wimse:agent-delegation-chain"
]
}
},
"x-security-note": "This agent is publicly accessible with no authentication required (noAuth). The ansIdentityCert scheme (mutual TLS, ANS private CA) is declared for future ANS-to-ANS production calls but is not currently enforced. The card accurately describes what is enforced."
}