{"audit":{"version":"1.5","generated_at":"2026-10-03T03:35:44.156891+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/whitemagic.dev","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"whitemagic.dev","name":"WhiteMagic Labs","url":"https://www.whitemagic.dev/.well-known/agent.json"}},"identity":{"provider":{"organization":"WhiteMagic Labs","url":"https://www.whitemagic.dev"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"1.2","supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"wrong_response","live_responds":false,"last_status_code":200,"last_elapsed_ms":559,"last_error":null},"track_record":{"first_seen":"2026-10-03T00:46:42.278888+00:00","last_checked":"2026-10-03T00:46:42.278888+00:00","last_seen_ok":"2026-10-03T00:46:42.278888+00:00","checks_total":1,"checks_ok":1,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":1,"archived":false,"archived_reason":null},"conformance":{"score":44,"grade":"D","summary":"D-grade: significant issues, auth-gated, partially broken, or stale.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":9,"max_points":10,"status":"partial","detail":"Declares A2A 1.2 but is missing v1.0 REQUIRED field: supportedInterfaces."},{"key":"live_responds","label":"Live JSON-RPC","points":5,"max_points":25,"status":"fail","detail":"Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response."},{"key":"protocol_version","label":"Protocol version","points":8,"max_points":10,"status":"partial","detail":"Declares A2A 1.2 but missing supportedInterfaces[] (required in v1.0, update your card to reach 10/10)."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 1 probe so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 6 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: WhiteMagic Labs (https://www.whitemagic.dev). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":5,"max_points":5,"status":"pass","detail":"declares 1 modern capability flag(s) (x402); seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":2,"max_points":5,"status":"partial","detail":"Declares 1 security scheme(s) but none use PKCE or mTLS."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://whitemagic.dev/.well-known/agent.json"},"skills":[{"id":"llm-context-dump","name":"LLM context dump","description":"Root-served /llms.txt (short index) and /llms-full.txt (comprehensive context) provide a complete, machine-readable picture of WhiteMagic Labs: capabilities, tool envelope contract, the real tool catalog, and discovery surfaces. Fetch in a single round-trip to ground your reasoning about the lab.","tags":["discovery","llm-context","well-known"],"examples":["Fetch GET /llms.txt for a short index.","Fetch GET /llms-full.txt for the comprehensive context dump."],"inputModes":["application/json"],"outputModes":["text/plain","application/json"]},{"id":"wm-meta-tool-routing","name":"Meta-tool routing (PRAY compression)","description":"The MCP surface exposes a single NLU-routed `wm` meta-router: invoke with {thought, route, args} – thought auto-routes to a tool via TF-IDF, route dispatches explicitly (e.g. 'memory.create'), args pass through. 70 routes are curated onto the default profile over the 307-capability full profile; tools/list exposes a 30-tool agent lifecycle surface. Say 'list tools' to the meta-tool to enumerate them.","tags":["pray","meta-tool","router","nlu"],"examples":["Invoke with {route:'memory.search', args:{query:'install decisions'}}","Invoke with {thought:'where did we leave off last session?'}","Say 'list tools' to the meta-tool to enumerate the 70 curated tools."],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"dharma-ethics-check","name":"Dharma ethical governance","description":"6 dharma_* functions: dharma_evaluate_ethics, dharma_check_boundaries, dharma_verify_consent, dharma_get_guidance, dharma_get_ethical_score, dharma_list_principles. Pre-flight any agent action through dharma_check_boundaries to detect ethical violations before commit.","tags":["dharma","ethics","governance","consent"],"examples":["POST {function:'dharma_check_boundaries', payload:{action:{type:'deploy',target:'production'}}}","POST {function:'dharma_list_principles', payload:{level:'ahimsa'}}"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"session-handoff","name":"Session handoff + context pack","description":"Session continuity is the core promise: session.start, session.record, session.checkpoint (verifiable handoff state auto-captured from git), session.continuity ('where we left off'), session.handoff (transfer/accept across devices), session.import/export (JSONL portability). Available via the wm meta-tool AND the `wm session` CLI without MCP transport.","tags":["session","handoff","checkpoint","continuity"],"examples":["Invoke the wm meta-tool with route:'session.continuity'.","Run `wm session continuity` in a terminal."],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"erc8004-agent-trust-validation","name":"ERC-8004 Task-Outcome Mapping","description":"Maps the core continuity-receipt verifier verdict plus task binding to an outcome. Issuer policy is not evaluated and anchors are not required. Five per-check fields are null (unreported): chain_integrity, signatures_valid, policy_compliant, resource_caps_respected, and anchors_verified. Returns an Ed25519-signed canonical JSON statement, which is not independent factual proof. The service does not submit onchain or settle transactions. Challenged via x402 ($0.01 USDC).","tags":["erc8004","task-outcome","validation","signed-statement","base"],"examples":["POST https://api.whitemagic.dev/erc8004/validate with task payload + continuity receipt bundle"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"memory-crystals-state-store","name":"Client-Encrypted Memory Crystals State Store","description":"Content-addressed encrypted agent state using the wm-crystal/1.0 envelope. Client-side ChaCha20-Poly1305 encryption protects plaintext while keys remain client-side. All reads and writes require an authenticated owner assertion mapped through the explicit owner registry; payment or a session pass alone does not establish ownership. Owner assignment is manual, with no automatic first-reader claim or self-service mapping flow. Existing unmapped legacy data remains held in protected quarantine until an explicit operator mapping is confirmed. For an already-mapped owner, GET /crystals/owner-locator returns the registry-mapped locator. Reads and lineage remain free and require authenticated owner scope. Reads use Cache-Control: private, no-store. Conditional ETag/304 responses are available only after owner authentication; no shared caching. Writes remain $0.02 USDC via x402.","tags":["memory-crystals","client-encryption","storage","encryption","persistence"],"examples":["POST https://api.whitemagic.dev/crystals with encrypted ciphertext and tag","GET https://api.whitemagic.dev/crystals/{id}","GET https://api.whitemagic.dev/crystals/lineage (authenticated owner scope)"],"inputModes":["application/json"],"outputModes":["application/json"]}],"provenance":[{"source":"smithery","first_seen":"2026-10-03T00:46:42.278888+00:00"}],"recent_probes":[{"fetched_at":"2026-10-03T00:46:42.278888+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":559,"live_responds":false}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-10-03T03:35:44.171448+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/whitemagic.dev/evidence","dispute_url":"https://agenstry.com/agents/whitemagic.dev/dispute"},"verification_history":[],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYWdlbnN0cnkuY29tLy53ZWxsLWtub3duL2p3a3MuanNvbiIsImtpZCI6ImFnZW50ZmluZGVyLWVzMjU2LTEiLCJ0eXAiOiJKT1NFIn0","signature":"QILyQ9PLY2dH37xAOA5VsQZYE1NXsRqXwvxNtINXB1Oxy67chtrswoyINo3fEJ6bUdxMuHYedXno4aogTF6pJw"}]}