{"audit":{"version":"1.4","generated_at":"2026-08-20T20:36:55.595669+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/agentnomos.com","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"agentnomos.com","name":"NOMOS Cross-Border Broker","url":"https://agentnomos.com/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"FeedOracle Technologies","url":"https://agentnomos.com"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"0.3.0","supports_streaming":false,"supports_push_notifications":true},"operational":{"live_state":"live","live_responds":true,"last_status_code":200,"last_elapsed_ms":24,"last_error":null},"track_record":{"first_seen":"2026-08-20T19:14:31.852473+00:00","last_checked":"2026-08-20T19:14:31.950276+00:00","last_seen_ok":"2026-08-20T19:14:31.950276+00:00","checks_total":2,"checks_ok":2,"uptime_pct":100.0,"archived":false,"archived_reason":null},"conformance":{"score":60,"grade":"C","summary":"C-grade: usable but has clear conformance issues, review the breakdown below.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":25,"max_points":25,"status":"pass","detail":"Endpoint responds to a negotiated A2A SendMessage probe (answers in ~1516 ms)."},{"key":"protocol_version","label":"Protocol version","points":5,"max_points":10,"status":"partial","detail":"Declares pre-1.0 A2A 0.3.0 (Google preview). Upgrade to v1.x for full points."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 2 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 8 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: FeedOracle Technologies (https://agentnomos.com). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":5,"max_points":5,"status":"pass","detail":"declares 2 modern capability flag(s) (ap2, x402); seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":0,"max_points":5,"status":"info","detail":"Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://agentnomos.com/.well-known/agent-card.json"},"skills":[{"id":"crossborder_preflight","name":"Cross-Border Regulatory Preflight","description":"Preflight classification for cross-border data flows between agent jurisdictions. Returns verdict (ALLOW/ALLOW_PUBLIC_SIGNAL_ONLY/REVIEW/BLOCK), blocked_fields, SCCs required, and evidence_hash. Advisory only — not legal advice, no regulatory certification.","tags":["regulatory","compliance","cross-border","gdpr","lgpd","ndpa","popia","data-transfer","preflight","eu"],"examples":["Can I transfer EU agent signals to a Brazil-based MCP server?","Preflight: EU source, Nigeria target, data_category: mcp_capability_signal"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"asia_market_scan","name":"Global Market Intelligence Scan","description":"Market intelligence from six regions (Japan, Singapore/China, India, Korea, Brazil/LatAm, Africa): MCP-ready companies, funded entities, compliance signals and EU-interest flags.","tags":["japan","singapore","india","korea","brazil","nigeria","africa","latam","mcp-ready","market-intelligence","funded"],"examples":["Find MCP-ready fintech companies in Nigeria today","Scan for EU-interest signals in Brazil/LatAm fintech"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"mcp_tool_discovery","name":"MCP Tool Discovery","description":"Discover MCP-compatible tools and servers across the OracleNet mesh. Returns capability profiles, endpoint URLs and protocol compatibility. Live counts are published in the mesh snapshot at https://tooloracle.io/.well-known/agent-pulse and are not frozen here.","tags":["mcp","discovery","tools","oraclenet","protocol"],"examples":["Find MCP servers with compliance tools for DORA","List available MCP tools for stablecoin risk assessment"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"a2a_handshake","name":"A2A Protocol Handshake","description":"Structured A2A handshake for agent discovery and capability negotiation. Returns protocol fit, supported modes and outreach queue status. The live endpoint speaks A2A 0.3 JSON-RPC (message/send, tasks/get, tasks/cancel) and additionally accepts A2A 1.0 request syntax on ingress (SendMessage, GetTask, CancelTask, and kind-less text parts). Responses are 0.3-shaped.","tags":["a2a","handshake","discovery","protocol","negotiation"],"examples":["Initiate A2A handshake with target agent in Singapore jurisdiction"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"x402_quote","name":"x402 Payment Quote","description":"Returns an x402 payment quote for AgentNOMOS purchase routes (USDC on Base, eip155:8453). Authoritative routes, prices and input schemas are published in the purchase manifest at https://agentnomos.network/.well-known/x402.json. Current routes: compliance_preflight $0.01, nomos/preflight $0.05, macro_snapshot $0.01. Quote and capped payment only — no autonomous settlement.","tags":["x402","payment","quote","usdc","base","micropayment"],"examples":["Get payment quote for crossborder_preflight EU to Japan"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"signed_receipt","name":"Signed Evidence Receipt","description":"Returns and verifies cryptographically signed receipts for completed NOMOS operations (SHA-256 sealed, Ed25519 signatures, public JWKS verification). Suitable for audit trails. Receipts prove what the NOMOS estate executed — execution-bound proof, not independent third-party attestation.","tags":["receipt","evidence","signing","audit","compliance","sha256"],"examples":["Get signed receipt for preflight operation receipt_id:xyz"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"agent_card_a2a_readiness","name":"NOMOS Agent-Card & A2A Readiness Check","description":"Deterministic readiness assessment of a public agent card / A2A discovery surface: identity, skills, protocol, authentication, commercial readiness, trust and security. Returns READY/WARN/NOT_READY with findings, machine-readable improvement suggestions, and a signed evidence digest. Offer descriptor: https://agentnomos.com/.well-known/nomos-a2a-offer.json.","tags":["agent-card","a2a","readiness","trust","x402"],"examples":["Assess https://example.com/.well-known/agent-card.json for A2A readiness"],"inputModes":["application/json"],"outputModes":["application/json","text/html"],"x402":{"price":"$0.10","currency":"USDC","network":"eip155:8453","scheme":"exact","resource":"https://tooloracle.io/v2/agent_card_a2a_readiness_v1","task_endpoint":"https://tooloracle.io/deal/a2a"},"transparency":{"schema":"nomos.transparency_disclosure.v1","component":"DealOracle","component_role":"automated NOMOS commercial-intake and demand-observation component","llm_use":"some DealOracle market- and intent-analysis functions may use an LLM","paid_product_method":"deterministic validation and decision rules (no LLM) for the paid Agent-Card/A2A Readiness Check","output_nature":"technical assessments and signed evidence","output_is_not":["certification","regulatory approval","legal opinion","legal-compliance determination","AI-Act conformity declaration","penetration test","security guarantee"],"operator_review":"operator review may be required for ambiguous or blocked cases","human_readable":"DealOracle is an automated NOMOS commercial-intake and demand-observation component. Some of its market- and intent-analysis functions may use an LLM. The paid Agent-Card / A2A Readiness Check itself runs on deterministic validation and decision rules and returns a technical assessment with signed evidence. It is not a certification, regulatory approval, legal opinion, legal-compliance determination, AI-Act conformity declaration, penetration test, or security guarantee. Operator review may be required for ambiguous or blocked cases."},"disclosure":"DealOracle is an automated NOMOS commercial-intake and demand-observation component. Some of its market- and intent-analysis functions may use an LLM. The paid Agent-Card / A2A Readiness Check itself runs on deterministic validation and decision rules and returns a technical assessment with signed evidence. It is not a certification, regulatory approval, legal opinion, legal-compliance determination, AI-Act conformity declaration, penetration test, or security guarantee. Operator review may be required for ambiguous or blocked cases.","role_binding":{"schema":"nomos.role_binding.v1","statement":"DealOracle operates as a delegated commercial-intake and demand-observation component of NOMOS under the published NOMOS operator identity and delegation credential.","operator_identity":"nomos.operator_identity.v1","operator_identity_url":"https://agentnomos.com/.well-known/nomos-identity.json","delegation_credential":"nomos.delegation_credential.v1","delegation_covers":["receiving paid self-service orders","delivering scans and reports","reading and attributing revenue"],"delegation_forbids":["autonomous spending","autonomous discounts","self-granting permissions","uncontrolled outreach"]},"limitations":["automated readiness assessment only","not certified","not regulator-approved","not AI-Act-compliant","not legally-compliant","not guaranteed-secure","not a penetration test"],"inputSchema":{"type":"object","properties":{"job_id":{"type":"string","description":"Job id from the x402 challenge binding"},"quote_id":{"type":"string","description":"Quote id from the x402 challenge binding"}}},"inputSchemaSource":{"origin":"https://tooloracle.io/openapi.json","path":"/v2/agent_card_a2a_readiness_v1","method":"POST","note":"Verbatim copy of the published requestBody schema for the invocation endpoint. Not authored for this card."}},{"id":"nomos_full_chain_verification","name":"Full-Chain Governed Verification","description":"Run one safe, read-only machine action through the complete NOMOS Machine Economy Trust Chain and receive a cryptographically verifiable execution receipt. The call binds the x402 payment, your stated intent (incl. your client_nonce), the pinned capability and offer, the NOMOS admission decision (which enforces current OracleNet security-freshness evidence), the execution and the response bytes into one Ed25519-signed receipt, verifiable against the public JWKS at https://feedoracle.io/.well-known/nomos-execution-jwks.json. Live x402 endpoint: POST https://tooloracle.io/v2/nomos_full_chain_verification — $0.001 USDC per call (USDC on Base, eip155:8453). Claim ceiling: execution-bound proof — not an independent third-party attestation, not a certification. Reproducibility references (ALLOW + DENY case, stateless verifier): https://agentnomos.com/.well-known/nomos-reproducibility.json Invocation note: this card is DISCOVERY ONLY for this skill — invoke it via x402 HTTP POST https://tooloracle.io/v2/nomos_full_chain_verification (payment required, $0.001 USDC on Base eip155:8453); A2A message/send does not execute this skill.","tags":["nomos","full-chain","verification","x402","receipts","governance"],"examples":["run one safe machine action through the full governed NOMOS chain and give me the signed receipt","prove end-to-end that intent, authorization, security evidence and execution are bound for this call"],"inputModes":["application/json"],"outputModes":["application/json"],"inputSchema":{"type":"object","properties":{"intent":{"type":"string","description":"Fixed action selector."},"client_nonce":{"type":"string","description":"Your correlation nonce; echoed and bound into the signed intent digest."}},"required":["intent","client_nonce"]},"inputSchemaSource":{"origin":"https://tooloracle.io/openapi.json","path":"/v2/nomos_full_chain_verification","method":"POST","note":"Verbatim copy of the published requestBody schema for the invocation endpoint. Not authored for this card."}}],"provenance":[{"source":"nanda_index","first_seen":"2026-08-20T19:14:31.852473+00:00"}],"recent_probes":[{"fetched_at":"2026-08-20T19:14:31.950276+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":24,"live_responds":true},{"fetched_at":"2026-08-20T19:14:31.852473+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":21,"live_responds":true}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-08-20T20:36:55.600762+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/agentnomos.com/evidence","dispute_url":"https://agenstry.com/agents/agentnomos.com/dispute"},"verification_history":[]}