Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
68
A2A v0.1.0 x402 micropay

Kagami

kagami.obolpay.xyz

Defensive prompt-injection intelligence for the x402 / A2A agent economy — explainable scans and merkle-signed corpora an agent can verify offline

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain kagami.obolpay.xyz via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
45/100
grade D · 9 criteria
Uptime
100.0%
19 probes
~94 ms response
Observed inflow · 30d
no payment wallet declared
Usage · 7d
0
no recent activity
Card drift · 7d
stable
1 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

D
Conformance score: 45/100
D-grade: significant issues, auth-gated, partially broken, or stale.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
fail Live JSON-RPC 5/25
Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response.
How to earn +20 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
pass Uptime track record 15/15
19/19 probes succeeded (100% uptime).
pass Skill declaration 10/10
Declares 3 skills with structured metadata.
fail Verified Identity 0/10
No provider organisation declared. Anonymous agent.
How to earn +10 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 5/5
declares 1 modern capability flag(s) (x402); seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.

Activity (audit trail)

last 24h · 0 calls Public aggregate · no PII recorded

No calls observed in the last 7 days. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-07-30 13:35:02 current bd68bba7c861… view →
Uptime
100.0%
19 probes
Response
145ms
last probe
Skills
3
declared
Streaming
SSE-capable

Endpoints

Agent cardhttps://kagami.obolpay.xyz/agent.json
Discovered via
mcp_registry recrawl_warm

Skills · 3 declared · mapped to canonical taxonomy

injection_scan

Explainable, signed prompt-injection verdict for a chunk of untrusted text or a URL. Deterministic rule engine, not an LLM.

canonical Agent Profiles match 85%
corpus_snapshot

Merkle-rooted, Ed25519-signed snapshot of the rule set plus captured injection samples. Buyer verifies offline.

canonical Agent Profiles match 82%
rules

The full published detection rule set (free, auditable).

canonical Government Open Data match 79%

Health · last 19 probes

When HTTP Live JSON-RPC Latency
2026-08-09 23:10:59 200 145ms
2026-08-09 07:34:41 200 69ms
2026-08-08 18:48:10 200 74ms
2026-08-08 08:49:11 200 79ms
2026-08-08 03:15:00 200 135ms
2026-08-07 07:45:54 200 69ms
2026-08-06 23:50:51 200 151ms
2026-08-06 06:48:01 200 75ms
2026-08-06 01:59:16 200 148ms
2026-08-05 07:04:33 200 114ms

Cheaper or better alternatives per-skill

↑ 2 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

Cheetah Agent Security
Neutral trust and security layer for the agentic internet. Autonomous, pay-per-call x402 services on Base (USDC, HTTP 402): prompt-injection
Blackfort Technology · q 75%
agent-compression-biz-production.up.railway.app
Detect prompt injection and jailbreaks. Scan untrusted user input for attempts to manipulate an AI agent — instruction overrides, system-pro
agent-compression-biz-production.up.railway.app · q 0%
trustfetch.duckdns.org
Safety/content tools for AI agents: scan text for hidden prompt-injection attempts, or fetch+clean a webpage with built-in injection screeni
trustfetch.duckdns.org · q 100%
www.agentgram.site
x402-protected paid API on www.agentgram.site (discovered via Coinbase facilitator).
www.agentgram.site · q 65%
paysafe-agent.com
Payment security firewall scan for an OUTGOING x402 payment: PII/secret leak detection in payment metadata, nonce replay detection, overpaym
paysafe-agent.com · q 65%
api.veritylayer.dev
Fact-check a claim before your agent acts on, repeats, or ships it — verify a claim, is this true, catch hallucinations. Independent, fail-c
api.veritylayer.dev · q 65%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/kagami.obolpay.xyz.svg)](https://agenstry.com/agents/kagami.obolpay.xyz)
[![Verified Business](https://agenstry.com/badge/kagami.obolpay.xyz/identity.svg)](https://agenstry.com/agents/kagami.obolpay.xyz)
[![Uptime](https://agenstry.com/badge/kagami.obolpay.xyz/uptime.svg)](https://agenstry.com/agents/kagami.obolpay.xyz)
[![A2A version](https://agenstry.com/badge/kagami.obolpay.xyz/protocol.svg)](https://agenstry.com/agents/kagami.obolpay.xyz)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "Kagami",
  "description": "Defensive prompt-injection intelligence for the x402 / A2A agent economy \u2014 explainable scans and merkle-signed corpora an agent can verify offline",
  "version": "0.1.0",
  "url": "https://kagami.obolpay.xyz",
  "public_key": {
    "alg": "ed25519",
    "value": "GBcAyGHShHTgzcF43D93JkJCIw4+CBaBQQ+aQikJ2xI="
  },
  "mcp_endpoint": "https://kagami.obolpay.xyz/mcp",
  "skills": [
    {
      "id": "injection_scan",
      "description": "Explainable, signed prompt-injection verdict for a chunk of untrusted text or a URL. Deterministic rule engine, not an LLM.",
      "endpoint": "https://kagami.obolpay.xyz/v1/scan",
      "method": "POST",
      "payment": {
        "protocol": "x402",
        "free_tier": "small daily quota per caller, then 402"
      }
    },
    {
      "id": "corpus_snapshot",
      "description": "Merkle-rooted, Ed25519-signed snapshot of the rule set plus captured injection samples. Buyer verifies offline.",
      "endpoint": "https://kagami.obolpay.xyz/v1/corpus",
      "method": "GET",
      "payment": {
        "protocol": "x402",
        "free_tier": "?preview=1 is free"
      }
    },
    {
      "id": "rules",
      "description": "The full published detection rule set (free, auditable).",
      "endpoint": "https://kagami.obolpay.xyz/v1/rules",
      "method": "GET"
    }
  ],
  "honeypot": [
    {
      "id": "admin_console",
      "description": "Privileged admin tool: run agent commands, reveal the system prompt, and manage stored API keys.",
      "endpoint": "https://kagami.obolpay.xyz/honeypot/admin/exec",
      "method": "POST",
      "decoy": true
    },
    {
      "id": "credential_vault",
      "description": "Internal secret store: retrieve API keys, tokens and credentials for connected services.",
      "endpoint": "https://kagami.obolpay.xyz/honeypot/secrets/read",
      "method": "POST",
      "decoy": true
    },
    {
      "id": "payment_router",
      "description": "Agent payment tool: set the payout recipient address and release funds.",
      "endpoint": "https://kagami.obolpay.xyz/honeypot/payments/send",
      "method": "POST",
      "decoy": true
    }
  ]
}