{"agent_host":"luigis.agent-desk.us","generated_at":"2026-09-20T05:40:08.601523+00:00","environment":"production","verified":true,"decision":"PASS","gates":[{"gate":1,"title":"Reachable agent endpoint (A2A + MCP)","status":"PASS","detail":"A2A: card valid; MCP: initialize + tools/list succeeded","evidence":{"agent_card":"https://luigis.agent-desk.us/.well-known/agent-card.json","card_sha256":"5e6c5679b305c58aa3116f53844200888215bc410e41826fa1368a0117d58d0b","skills":["get_business_info","get_hours","get_menu_or_services","place_order","make_booking","get_confirmation"],"mcp_url":"https://luigis.agent-desk.us/mcp","mcp_tools":["get_business_info","get_hours","get_menu_or_services","place_order","make_booking","get_confirmation"]}},{"gate":2,"title":"Public HTTPS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","evidence":{"tls_version":"TLSv1.3","leaf_sha256":"79803e13e228ebe35111b4591e01103e2c4634846f9d0d4cf6688426f419467f","issuer":"CN=YE2,O=Let's Encrypt,C=US","not_after":"2026-12-19T02:44:10+00:00"}},{"gate":3,"title":"Owned MLH domain","status":"PASS","detail":"host is under BASE_DOMAIN, serves valid public TLS, and ANS validated control of its DNS (ACME DNS-01)","evidence":{"base_domain":"agent-desk.us","agent_host":"luigis.agent-desk.us"}},{"gate":4,"title":"Production ANS registration ACTIVE","status":"PASS","detail":"GoDaddy production ANS reports ACTIVE (live lookup)","evidence":{"agent_id":"9ec315f6-408e-41d4-99f1-20b6f083a080","ans_name":"ans://v1.0.0.luigis.agent-desk.us","ans_status":"ACTIVE","environment":"production","checked_at":"2026-09-20T05:40:06.340247+00:00"}},{"gate":5,"title":"Verification evidence","status":"PASS","detail":"all mandatory checks passed","evidence":{"checks_passed":15,"checks_total":15,"identity_sha256":"d725a87e9952b61daac75f8c1da032e35afee1886279e314690b215ae9b846ea"}}],"verification":{"agent_host":"luigis.agent-desk.us","generated_at":"2026-09-20T05:40:08.601523Z","ans":{"agent_id":"9ec315f6-408e-41d4-99f1-20b6f083a080","ans_name":"ans://v1.0.0.luigis.agent-desk.us","status":"ACTIVE","environment":"production","declared_endpoints":[{"protocol":"A2A","url":"https://luigis.agent-desk.us/a2a","transports":["JSON-RPC"],"metadata_url":"https://luigis.agent-desk.us/.well-known/agent-card.json"},{"protocol":"MCP","url":"https://luigis.agent-desk.us/mcp","transports":["STREAMABLE-HTTP"],"metadata_url":"https://luigis.agent-desk.us/.well-known/mcp.json"}],"checked_at":"2026-09-20T05:40:06.340247Z","source":"GoDaddy ANS public discovery API (live)"},"endpoint_checks":[{"protocol":"A2A","url":"https://luigis.agent-desk.us/a2a","status":"PASS","detail":"card valid"},{"protocol":"MCP","url":"https://luigis.agent-desk.us/mcp","status":"PASS","detail":"initialize + tools/list succeeded"}],"identity_certificate":{"issuer":"CN=GoDaddy Private ANS Issuing CA - PR1v1,O=GoDaddy.com,C=US","subject":"CN=luigis.agent-desk.us","san":["DNS:luigis.agent-desk.us","URI:ans://v1.0.0.luigis.agent-desk.us"],"serial":"1A0BCEAF38C003CEBFACC49C4D7F2000197","sha256":"d725a87e9952b61daac75f8c1da032e35afee1886279e314690b215ae9b846ea","valid_from":"2026-09-20T03:45:09Z","valid_to":"2027-09-20T03:45:09Z","chain_status":"PASS","chain_reason":"chain verifies to the provisioned ANS trust anchor","binding_status":"PASS","binding_reason":"validity window, host and ANS name binding verified; fingerprint matches the transparency-log attestation"},"tls":{"status":"PASS","detail":"hostname and chain verified against the public WebPKI","version":"TLSv1.3","cipher":"TLS_AES_128_GCM_SHA256","hostname_verified":true,"leaf_sha256":"79803e13e228ebe35111b4591e01103e2c4634846f9d0d4cf6688426f419467f","issuer":"CN=YE2,O=Let's Encrypt,C=US","subject":"CN=luigis.agent-desk.us","san":["DNS:luigis.agent-desk.us"],"not_after":"2026-12-19T02:44:10Z"},"a2a":{"status":"PASS","detail":"card valid","card_url":"https://luigis.agent-desk.us/.well-known/agent-card.json","card_valid":true,"card_sha256":"5e6c5679b305c58aa3116f53844200888215bc410e41826fa1368a0117d58d0b","name":"Luigi's Brick Oven Pizza","version":"1.0.0","protocol_versions":["1.0"],"skills":["get_business_info","get_hours","get_menu_or_services","place_order","make_booking","get_confirmation"],"rpc_url":"https://luigis.agent-desk.us/a2a","signed":true,"drift":false},"mcp":{"status":"PASS","detail":"initialize + tools/list succeeded","url":"https://luigis.agent-desk.us/mcp","handshake":true,"protocol_version":"2025-03-26","server_name":"agent-desk-business-agent","tools":["get_business_info","get_hours","get_menu_or_services","place_order","make_booking","get_confirmation"],"probe_tool":"get_hours","probe_ok":true},"checks":[{"id":"ans_status_active","label":"ANS lifecycle is ACTIVE (live)","status":"PASS","detail":"registry reports ACTIVE","mandatory":true,"evidence":{"agent_id":"9ec315f6-408e-41d4-99f1-20b6f083a080","ans_name":"ans://v1.0.0.luigis.agent-desk.us"}},{"id":"canonical_agent_host","label":"Canonical agent host","status":"PASS","detail":"registry agentHost and ANS name match the requested host","mandatory":true,"evidence":{"expected":"luigis.agent-desk.us","observed":"luigis.agent-desk.us"}},{"id":"supported_protocol","label":"Supports A2A or MCP","status":"PASS","detail":"A2A, MCP","mandatory":true,"evidence":{}},{"id":"endpoints_https","label":"Endpoints are HTTPS with valid TLS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","mandatory":true,"evidence":{"tls_version":"TLSv1.3","leaf_sha256":"79803e13e228ebe35111b4591e01103e2c4634846f9d0d4cf6688426f419467f"}},{"id":"endpoint_host_binding","label":"Endpoints are on the registered host","status":"PASS","detail":"every endpoint/metadata URL is on the registered agentHost","mandatory":true,"evidence":{}},{"id":"endpoint_network_policy","label":"Endpoints pass outbound network policy","status":"PASS","detail":"https/443, public DNS name, every resolved address globally routable","mandatory":true,"evidence":{}},{"id":"ans_record_consistency","label":"Registry detail and transparency log agree","status":"PASS","detail":"search hit, agent detail and transparency-log badge are consistent","mandatory":true,"evidence":{"badge_status":"ACTIVE"}},{"id":"identity_certificate_retrieved","label":"Identity certificate retrieved from ANS","status":"PASS","detail":"retrieved from the official certificate-management API","mandatory":false,"evidence":{"sha256":"d725a87e9952b61daac75f8c1da032e35afee1886279e314690b215ae9b846ea"}},{"id":"identity_certificate_binding","label":"Identity certificate validity and binding","status":"PASS","detail":"validity window, host and ANS name binding verified; fingerprint matches the transparency-log attestation","mandatory":false,"evidence":{}},{"id":"identity_chain_trust_anchor","label":"Identity certificate chains to the ANS trust anchor","status":"PASS","detail":"chain verifies to the provisioned ANS trust anchor","mandatory":false,"evidence":{}},{"id":"metadata_fetch","label":"Protocol metadata fetched within limits","status":"PASS","detail":"fetched with time/size/content-type limits","mandatory":true,"evidence":{}},{"id":"metadata_schema","label":"Metadata parses and matches the registration","status":"PASS","detail":"parsed as data; interface matches the registration","mandatory":true,"evidence":{}},{"id":"metadata_integrity","label":"Metadata signature / hash","status":"PASS","detail":"card is signed by the key in the ANS-issued identity certificate","mandatory":false,"evidence":{"identity_sha256":"d725a87e9952b61daac75f8c1da032e35afee1886279e314690b215ae9b846ea"}},{"id":"card_hash_drift","label":"Agent Card hash is stable (drift watch)","status":"PASS","detail":"matches the last verified hash","mandatory":true,"evidence":{"card_sha256":"5e6c5679b305c58aa3116f53844200888215bc410e41826fa1368a0117d58d0b"}},{"id":"local_blocklist","label":"Not on the local blocklist","status":"PASS","detail":"no local block","mandatory":true,"evidence":{}}],"verified":true,"decision":"PASS","reasons":[]},"notes":["Statuses are derived from live checks only; INCOMPLETE means 'could not be proven', never 'assumed fine'.","An ANS identity identifies an agent; it does not make the agent's output trusted."],"cached":false}