{"audit":{"version":"1.4","generated_at":"2026-08-19T19:06:24.336916+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/mcp.viridis-security.com","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"mcp.viridis-security.com","name":"Viridis MCP","url":"https://mcp.viridis-security.com/.well-known/agent.json"}},"identity":{"provider":{"organization":"Viridis North LLC","url":"https://github.com/viridis-security"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":null,"supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"wrong_response","live_responds":false,"last_status_code":200,"last_elapsed_ms":126,"last_error":null},"track_record":{"first_seen":"2026-08-18T00:29:29.197886+00:00","last_checked":"2026-08-19T09:33:31.438847+00:00","last_seen_ok":"2026-08-19T09:33:31.438847+00:00","checks_total":4,"checks_ok":4,"uptime_pct":100.0,"archived":false,"archived_reason":null},"conformance":{"score":36,"grade":"F","summary":"F-grade: card is reachable but fails most operational signals.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":5,"max_points":25,"status":"fail","detail":"Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response."},{"key":"protocol_version","label":"Protocol version","points":0,"max_points":10,"status":"fail","detail":"No protocolVersion in card."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 4 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 3 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: Viridis North LLC (https://github.com/viridis-security). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":4,"max_points":5,"status":"pass","detail":"seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":2,"max_points":5,"status":"partial","detail":"Declares 1 security scheme(s) but none use PKCE or mTLS."}]},"card_read":{"findings":[{"field":"securitySchemes","problem":"Input should be a valid dictionary","action":"dropped","detail":"this field was not indexed"}],"clean":false,"source_url":"https://mcp.viridis-security.com/.well-known/agent.json"},"skills":[{"id":"injection.detect","name":"Adversarial Injection Detection","description":"Classify untrusted text as clean / suspicious / attack. Returns verdict, probability, bits-at-risk per Adversarial Landauer Inequality, matched VulnCanon entries, and a recommended action (allow / sanitize / reject / escalate). Backed by T-IB-02 + T-IB-06.","tags":["security","prompt-injection","ai-agent","attribution","aristotle-verified"],"examples":["Classify this user input before passing it to an LLM tool","Return bits-at-risk for an agent prompt before execution","Get a recommended action for a suspicious context insertion"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"canon.scan","name":"VulnCanon Source Scan","description":"Match source code against the public VulnCanon catalog of AI-agent vulnerability classes (SSRF in fetch tools, prompt injection patterns, tool-poisoning, cross-agent state pollution, etc.). Returns matched entry IDs, severity, occurrence line, and mitigation references. Backed by T-IB-05 Canon Compression.","tags":["security","code-review","vulncanon","static-analysis","aristotle-verified"],"examples":["Scan this agent tool implementation for known vulnerability patterns","Check a code snippet for AI-agent-specific security risks before deploy"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"maxwell.challenge","name":"Maxwell Adaptive Proof-of-Work","description":"Issue an Argon2id proof-of-work challenge that an upstream attacker must solve. Defender pays log2(1/alpha) times the attacker's energy per bit, making sustained adversarial input energetically irrational. Backed by T-IB-09 Adversarial Dissipation. Tier-gated (Growth+) on the hosted endpoint; Apache-2.0 reference implementation available.","tags":["security","rate-limiting","proof-of-work","asymmetric-defense","aristotle-verified"],"examples":["Issue a PoW challenge to throttle a suspicious agent caller","Verify a PoW solution and grant downstream access"],"inputModes":["application/json"],"outputModes":["application/json"]}],"provenance":[{"source":"mcp_registry","first_seen":"2026-08-18T00:29:29.197886+00:00"}],"recent_probes":[{"fetched_at":"2026-08-19T09:33:31.438847+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":126,"live_responds":false},{"fetched_at":"2026-08-18T19:45:43.838942+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":105,"live_responds":false},{"fetched_at":"2026-08-18T09:02:00.744068+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":116,"live_responds":false},{"fetched_at":"2026-08-18T00:29:29.197886+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":92,"live_responds":false}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-08-19T19:06:24.342408+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/mcp.viridis-security.com/evidence","dispute_url":"https://agenstry.com/agents/mcp.viridis-security.com/dispute"},"verification_history":[]}