{"audit":{"version":"1.5","generated_at":"2026-10-02T07:24:37.859308+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/coderifts.com","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"coderifts.com","name":"CodeRifts","url":"https://coderifts.com/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"CodeRifts","url":"https://coderifts.com"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"1.0","supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"no_url","live_responds":null,"last_status_code":200,"last_elapsed_ms":56,"last_error":null},"track_record":{"first_seen":"2026-10-02T05:39:45.868992+00:00","last_checked":"2026-10-02T05:39:45.868992+00:00","last_seen_ok":"2026-10-02T05:39:45.868992+00:00","checks_total":1,"checks_ok":1,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":1,"archived":false,"archived_reason":null},"conformance":{"score":51,"grade":"D","summary":"D-grade: significant issues, auth-gated, partially broken, or stale.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":10,"max_points":25,"status":"partial","detail":"Card declares only gRPC / HTTP+JSON interfaces; the live probe covers JSON-RPC, so the endpoint was not exercised. Not a defect in the card."},{"key":"protocol_version","label":"Protocol version","points":10,"max_points":10,"status":"pass","detail":"Declares A2A 1.0 with supportedInterfaces[] (current v1 card shape)."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 1 probe so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 3 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: CodeRifts (https://coderifts.com). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":4,"max_points":5,"status":"pass","detail":"seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":2,"max_points":5,"status":"partial","detail":"Declares 2 security scheme(s) but none use PKCE or mTLS."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://coderifts.com/.well-known/agent-card.json"},"skills":[{"id":"preflight_change_set","name":"preflight_change_set","description":"Use this when: a contract artifact (OpenAPI, GraphQL, protobuf, AsyncAPI, MCP manifests, or agent tool schemas) changes before merge, deploy, publish, or tool registration; AND any agent-executed operation with no supported contract type — send type agent_operation. Do not call for documentation-only changes, static readiness scoring, or receipt verification. Use analyze for risk only; authorize requires context.operation. Skipping this call is not permission. Absence of a key is not permission. Inputs: preflight_mode is required: \"analyze\" (risk only; no receipt, no execution_action) or \"authorize\" (may mint a receipt; requires context.operation — merge is not deploy is not publish). Supply exactly one artifact source: artifacts[] (1–20 items, each {id, type, before, after} as the FULL spec/schema text, not a path or URL; type is openapi|graphql|grpc|asyncapi|mcp_manifest|agent_tools|agent_operation) XOR derivation=\"server\" (server reads GitHub Compare; needs context.repository + context.base + context.head; sending artifacts[] together is 400). Grant fields sit in one object, execution_grant_request {include_execution_grant, grant_version, tenant_id, executor_id, adapter_id, target_uri, expected_state_token, state_nonce, audience, policy_hash}; analyze ignores it; required is preflight_mode only. previous_receipt is a chain token base64url(body).base64url(signature) to LINK a prior decision — it does not re-verify; use coderifts.verify_receipt instead; for details of a past decision use coderifts.get_decision_details instead. idempotency_key replays authorize only (24h), never analyze.","tags":["analyze","authorize"],"examples":[],"inputModes":[],"outputModes":[]},{"id":"verify_receipt","name":"verify_receipt","description":"Verify a CodeRifts signed chain-receipt you ALREADY HOLD: cryptographic\nauthenticity (signature + key id), body binding, and — when lifecycle indices\nare available — whether it is currently valid authorization (not expired,\nsuperseded, or revoked) for a stated operation/target.\n\nUse this when:\n- You already obtained a chain_receipt / receipt token from a prior preflight\n  (or CI artifact) and are about to act (merge/deploy) under that receipt.\n- A contract-gate or policy requires offline/online proof that the receipt is\n  authentic for this change before proceeding.\n- You must distinguish \"signature ok\" from \"currently authorized\" (stale or\n  superseded receipts must not be treated as live approval).\n\nDo not use when:\n- You do not have a receipt yet — call coderifts.preflight_change_set first.\n- You need a NEW decision for a changed base→head set — preflight again;\n  verify_receipt does not re-diff specs.\n- The receipt you hold binds a different operation or target than the one you\n  are about to perform — call coderifts.preflight_change_set with\n  context.operation set to that operation (a merge receipt does not authorize\n  a deploy); verify_receipt cannot re-scope or re-issue a decision.\n- You only need human-readable history of an old decision_id without a receipt\n  token — use coderifts.get_decision_details.\n- The change set itself is unknown or incomplete — fix the change set and\n  preflight; do not \"verify\" a placeholder.\n\nInputs: receipt token (required); target_id = decision_result.artifact_digest — required\nfor an authorization verdict; omitted → target_not_stated. Optional intended context\n(operation, environment, fingerprint, audience, repository/branch/pull_request, base/head)\nand the body_hash-bound decision_result envelope. 30s clock-skew leeway on expiry. A 0s\ngrace for declared destructive production operations is defined in the policy but\nis unreachable today: the intended-context schema has no destructive field, so\nnothing can declare one and the 30s leeway always applies.\nReturns { valid, status, currently_authorized (bool|null), reason, payload, authz_* }.\nBranch on currently_authorized; null = not evaluated.\n\nWhen a decision envelope is also in hand (e.g. from a prior preflight), its\ncontrol_envelope.next_agent_step (if present) is structured remediation guidance\nthe agent MAY follow after a non-CONTINUE decision — still branch on\nexecution_action; next_agent_step is suggestion, not permission.","tags":["verify","receipt"],"examples":[],"inputModes":[],"outputModes":[]},{"id":"get_decision_details","name":"get_decision_details","description":"Retrieve a PAST CodeRifts decision by exactly one identifier\n(case_id | decision_id | fingerprint): full report, breaking changes, scores,\nand linked receipt metadata if stored.\n\nUse this when:\n- You have a decision_id (or fingerprint) from a previous preflight, PR\n  comment, or CI log and need to inspect or explain that past decision.\n- You are auditing why a prior ALLOW/WARN/BLOCK was issued.\n- You are NOT requesting a new analysis of current before/after specs.\n\nDo not use when:\n- You need a decision for the CURRENT uncommitted or PR head change set —\n  call coderifts.preflight_change_set with the current artifacts.\n- You hold a receipt token and only need cryptographic/lifecycle verification —\n  use coderifts.verify_receipt.\n- You have no identifier — run preflight first to create one.\n\nInputs: exactly one of case_id, decision_id, or fingerprint. {} → INVALID_INPUT;\ntwo identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id → CASE_NOT_FOUND\n(lookup never opens a case). Returns the stored document or not_found.\n\nScoping — fingerprint lookup returns only YOUR OWN decisions. A fingerprint is\nderived from content, not from an account, so two callers who preflight\nbyte-identical specs derive the same one; the lookup is therefore constrained\nto the decisions your credential can prove it owns.\n\nA decision that exists but is not yours returns the SAME not_found as one that\nwas never issued. This is deliberate: a distinguishable \"exists but forbidden\"\nwould confirm to any caller that a given content hash had been decided on by\nsomeone, which is the fact the scoping exists to withhold. Do not read\nnot_found as proof that no such decision exists anywhere.\n\nDecisions persisted without context.repository cannot currently be attributed\nto an account, and are not retrievable by fingerprint at all — not by their\nowner either. Retrieve those by decision_id, which is unchanged and unscoped.\nThis is a limitation of what older stored rows carry, not a property of the\nlookup: rows written from now on record the account directly, so the gap\nnarrows as older rows age out. If a fingerprint you expect returns not_found,\nuse the decision_id before concluding the decision is missing.\n\nWhen the stored envelope carries control fields, control_envelope.next_agent_step\nis structured remediation guidance the agent MAY follow for non-CONTINUE\nexecution_action values (null on CONTINUE*). Still branch on execution_action;\nnext_agent_step is a suggestion, not permission.","tags":["decision"],"examples":[],"inputModes":[],"outputModes":[]}],"provenance":[{"source":"smithery","first_seen":"2026-10-02T05:39:45.868992+00:00"}],"recent_probes":[{"fetched_at":"2026-10-02T05:39:45.868992+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":56,"live_responds":null}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-10-02T07:24:37.875675+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/coderifts.com/evidence","dispute_url":"https://agenstry.com/agents/coderifts.com/dispute"},"verification_history":[]}