{"audit":{"version":"1.5","generated_at":"2026-09-08T20:23:44.344850+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/kopass.app","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"kopass.app","name":"KoPass","url":"https://kopass.app/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"ALEXOPS","url":"https://kopass.app"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"1.0","supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"live","live_responds":true,"last_status_code":200,"last_elapsed_ms":16,"last_error":null},"track_record":{"first_seen":"2026-09-07T20:19:26.237136+00:00","last_checked":"2026-09-08T15:16:37.873410+00:00","last_seen_ok":"2026-09-08T15:16:37.873410+00:00","checks_total":4,"checks_ok":4,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":4,"archived":false,"archived_reason":null},"conformance":{"score":64,"grade":"C","summary":"C-grade: usable but has clear conformance issues, review the breakdown below.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":25,"max_points":25,"status":"pass","detail":"Endpoint responds to a negotiated A2A SendMessage probe (answers in ~22 ms)."},{"key":"protocol_version","label":"Protocol version","points":10,"max_points":10,"status":"pass","detail":"Declares A2A 1.0 with supportedInterfaces[] (current v1 card shape)."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 4 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 7 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: ALEXOPS (https://kopass.app). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":4,"max_points":5,"status":"pass","detail":"seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":0,"max_points":5,"status":"info","detail":"Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://kopass.app/.well-known/agent-card.json"},"skills":[{"id":"a2a_ecosystem","name":"A2A ecosystem, measured","description":"How many projects use the A2A (Agent2Agent) protocol, counted daily from declared repository topics: total, created in the last year, active, dormant, abandoned, and by language. Every figure carries the date it was measured.","tags":["a2a","measurement","ecosystem"],"examples":["How many projects actually use A2A?"],"inputModes":[],"outputModes":[]},{"id":"mcp_ecosystem","name":"MCP ecosystem, measured","description":"How many servers are published for the Model Context Protocol, counted daily from the official registry, with the same breakdown and the date of the reading.","tags":["mcp","measurement","ecosystem"],"examples":["How many MCP servers exist?"],"inputModes":[],"outputModes":[]},{"id":"search_tools","name":"Search the measured catalogue","description":"Search the KoPass catalogue of developer tools, libraries, CLIs, MCP servers and agent skills. Results come from daily readings, never from an editorial list.","tags":["catalogue","search","tools"],"examples":["Find measured MCP servers for Postgres."],"inputModes":[],"outputModes":[]},{"id":"find_agents_by_capability","name":"Find an A2A agent by capability","description":"Find deployed A2A agents by the skills they declare, among those whose card KoPass read at their own well-known location and that still answered on the latest reading. Each result carries the date it last answered.","tags":["a2a","discovery","agents"],"examples":["Which agent can issue an invoice?"],"inputModes":[],"outputModes":[]},{"id":"agent_record","name":"Everything known about one agent","description":"Return the full record KoPass holds for one A2A agent, by its host name: declared skills, conformance verdict, protocol version, since when it has been followed, and the date it last answered.","tags":["a2a","agents","history"],"examples":["Is the agent at example.com still answering?"],"inputModes":[],"outputModes":[]},{"id":"a2a_conformance","name":"A2A card conformance, measured","description":"Return the dated conformance figures across every agent card KoPass reads daily: how many are conformant, how many still use the shape from before v1.0, how many are signed, and the most frequent faults.","tags":["a2a","conformance","measurement"],"examples":["How many A2A agent cards actually follow the specification?"],"inputModes":[],"outputModes":[]},{"id":"validate_agent_card","name":"Validate an A2A agent card","description":"Read the agent card published at an address and report what the A2A specification says about it, field by field, including whether it uses the shape from before v1.0.","tags":["a2a","validation","conformance"],"examples":["Is the agent card at example.com valid?"],"inputModes":[],"outputModes":[]}],"provenance":[{"source":"lists","first_seen":"2026-09-07T20:19:26.237136+00:00"}],"recent_probes":[{"fetched_at":"2026-09-08T15:16:37.873410+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":16,"live_responds":true},{"fetched_at":"2026-09-08T08:27:55.448964+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":15,"live_responds":true},{"fetched_at":"2026-09-08T02:20:34.265345+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":15,"live_responds":true},{"fetched_at":"2026-09-07T20:19:26.237136+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":19,"live_responds":true}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-09-08T20:23:44.356993+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/kopass.app/evidence","dispute_url":"https://agenstry.com/agents/kopass.app/dispute"},"verification_history":[],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYWdlbnN0cnkuY29tLy53ZWxsLWtub3duL2p3a3MuanNvbiIsImtpZCI6ImFnZW50ZmluZGVyLWVzMjU2LTEiLCJ0eXAiOiJKT1NFIn0","signature":"HRA2SKzBrEgtqNaw2MXclofzmZLnTC3FFmD-Oq1nA8HJecPPtz2PdASQ-FzORszbzpyCcwlJx1QcyY-ZL_iZpw"}]}