{"audit":{"version":"1.5","generated_at":"2026-09-08T20:58:34.229886+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/ai.rjhsignaltech.workers.dev","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"ai.rjhsignaltech.workers.dev","name":"RJH Signal email-authentication reader","url":"https://ai.rjhsignaltech.workers.dev/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"RJH Signal Technologies LLC","url":"https://ai.rjhsignaltech.workers.dev"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"0.3.0","supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"live","live_responds":true,"last_status_code":200,"last_elapsed_ms":21,"last_error":null},"track_record":{"first_seen":"2026-09-05T19:34:16.303868+00:00","last_checked":"2026-09-07T02:02:12.150047+00:00","last_seen_ok":"2026-09-07T02:02:12.150047+00:00","checks_total":3,"checks_ok":3,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":3,"archived":false,"archived_reason":null},"conformance":{"score":59,"grade":"D","summary":"D-grade: significant issues, auth-gated, partially broken, or stale.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":25,"max_points":25,"status":"pass","detail":"Endpoint responds to a negotiated A2A SendMessage probe (answers in ~29 ms)."},{"key":"protocol_version","label":"Protocol version","points":5,"max_points":10,"status":"partial","detail":"Declares pre-1.0 A2A 0.3.0 (Google preview). Upgrade to v1.x for full points."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 3 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 4 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: RJH Signal Technologies LLC (https://ai.rjhsignaltech.workers.dev). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":4,"max_points":5,"status":"pass","detail":"seen in upstream source within 1d"},{"key":"security","label":"Security declaration","points":0,"max_points":5,"status":"info","detail":"Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://ai.rjhsignaltech.workers.dev/.well-known/agent-card.json"},"skills":[{"id":"email-authentication-read","name":"Read a domain's SPF and DMARC","description":"Send a message whose text contains one bare domain name, for example example.com. This is the default reading: a message that names none of the other three gets this one. Returns that domain's SPF record, the DNS lookups it costs a receiver counted against the limit of 10 in RFC 7208 section 4.6.4, the include tree, and its DMARC record with every tag parsed. Read live from public DNS at the moment of the call on Cloudflare 1.1.1.1 and Google 8.8.8.8; where both resolvers return records and the records differ the disagreement is reported rather than resolved, and where one returns records and the other returns nothing the records are reported and the resolver that returned them is named.","tags":["dns","spf","dmarc","email-authentication","deliverability"],"examples":["example.com","Is wisconsin.gov over the SPF lookup limit?"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]},{"id":"mta-sts-read","name":"Read a domain's MTA-STS policy and TLS-RPT record","description":"Send a message containing one bare domain name and the words mta-sts or tls-rpt. Reads the _mta-sts TXT record, fetches the policy at https://mta-sts.<domain>/.well-known/mta-sts.txt over HTTPS and parses its version, mode, max_age and MX patterns, and reads the _smtp._tls TLS-RPT record. An unreachable or malformed policy is reported as what it is rather than treated as an absent one, and the policy id published in DNS is reported beside the policy that was actually fetched and its HTTP status.","tags":["dns","mta-sts","tls-rpt","smtp","email-authentication"],"examples":["mta-sts for gmail.com","Does example.com publish a TLS-RPT record?"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]},{"id":"dmarc-report-destination-read","name":"Check DMARC report destinations under RFC 7489 section 7.1","description":"Send a message containing one bare domain name and the word rua, ruf, or report destinations. Extracts every rua and ruf address from the domain's DMARC record, decides which are external, and for each external destination queries <domain>._report._dmarc.<destination>. It always asks twice, never once: a second query with a sender label that cannot exist, because RFC 7489 section 7.1 lets a report receiver publish a wildcard at *._report._dmarc that answers for any sender, and a single query reports that wildcard as an arrangement specific to the caller's domain. The RFC compares Organizational Domains, which needs the public suffix list; this agent compares names instead - identical, or either a subdomain of the other - and says so in every answer, naming the direction of the error.","tags":["dns","dmarc","rfc7489","reporting","email-authentication"],"examples":["Are wisconsin.edu's rua destinations authorised?","rua check for example.com"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]},{"id":"mcp-discovery-read","name":"Read what an indexer sees at a public MCP endpoint","description":"Send a message containing the full https address of an MCP endpoint, for example https://example.com/mcp. Reports what an unauthenticated indexer would record about it: the result of an MCP initialize call, the result of tools/list including every tool name and whether each carries a description, and the HTTP status of the nine discovery documents named crawlers actually request from MCP hosts. Nothing is called on the target beyond initialize and tools/list and nothing is stored about it. This agent runs on Cloudflare Workers and declines to read a workers.dev origin from inside that platform rather than print a reading it knows is wrong.","tags":["mcp","discovery","agent-tooling","http"],"examples":["https://example.com/mcp","What does an indexer see at https://mcp.example.org/mcp ?"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]}],"provenance":[{"source":"manifests","first_seen":"2026-09-05T19:34:16.303868+00:00"}],"recent_probes":[{"fetched_at":"2026-09-07T02:02:12.150047+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":21,"live_responds":true},{"fetched_at":"2026-09-06T01:32:44.521740+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":25,"live_responds":true},{"fetched_at":"2026-09-05T19:34:16.303868+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":27,"live_responds":true}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-09-08T20:58:34.235493+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/ai.rjhsignaltech.workers.dev/evidence","dispute_url":"https://agenstry.com/agents/ai.rjhsignaltech.workers.dev/dispute"},"verification_history":[],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYWdlbnN0cnkuY29tLy53ZWxsLWtub3duL2p3a3MuanNvbiIsImtpZCI6ImFnZW50ZmluZGVyLWVzMjU2LTEiLCJ0eXAiOiJKT1NFIn0","signature":"tWfgKd6oIrmPHAteWrTHonvAh57iBMDXBIDBDTslcdcsU3URSVyuGZHHarCqIxN-xH7hygO6U4agxQ6sKfVNmg"}]}