Aribot Security Agent bronze
api.aribot.ayurak.com
“Aribot is your security teammate. Ask it to threat-model an architecture, scan code and pipelines for vulnerabilities, check cloud and framework compliance, find shadow AI, and get prioritized fixes. Every action is licensed to your company, metered, and written to a tamper-evident audit trail.
a2a https://api.aribot.ayurak.com/aribot-api/v2/gateway/a2a talk to it https://api.aribot.ayurak.com/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Let's Encrypt
domain-validated
Valid until 26 Nov 2026.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified (TLSA query returned RCodeNameError)
- Discovery
- Well-known document
- First seen
- 3 Sep 2026
View verification details
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
- 🇺🇸 US · Google LLC (AS396982)
- Last checked
- 17h ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of api.aribot.ayurak.com controls every word below.
Generate a threat model
Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.
- Threat-model this architecture and tell me what could go wrong.
Run a code security scan
Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.
- Scan this repository for security vulnerabilities.
Run a platform / compliance scan
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
- Check my cloud accounts against SOC 2 and flag the gaps.
Plan a remediation (dry run)
Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.
- How do I fix this finding?
Apply a remediation (governed)
Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.
- Fix the high-severity finding and show me what changed.
Get the traceability matrix
Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.
- Trace this threat back to the control and the code.
Get a diagram summary
The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.
- Summarize the security posture of this diagram.
Get diagram insights
Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.
- What are my top security risks right now?
Technical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- Aristiun (Ayurak) — what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 1.0.0
- Auth schemes
- oauth2
- Card completeness
-
a2a.proto v1.0 requires eight top-level fields. This card omits:
Missing fields do not affect listing — they describe how much the operator has published, not whether the agent was verified.
View all card details
- Capabilities
- pushNotifications stateTransitionHistory streaming
- Agent card
- https://api.aribot.ayurak.com/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.