agenttru.st

Hacker Bob public records bronze

bob-site-5i9.pages.dev

Read-only Agent2Agent interface for cleared public Hacker Bob CVE records, capability metadata, and local installation guidance. It cannot run assessments or interact with targets.

https://bob-site-5i9.pages.dev/.well-known/agent-card.json its card
Checked 1d ago extendedAgentCard, pushNotifications, streaming

we checked this    the operator says this

Community rating 0 0 up · 0 down — sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Google Trust Services domain-validated
Valid until 3 Nov 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified
Discovery
Well-known document
This host also publishes an ARD catalog (/.well-known/ai-catalog.json) declaring 12 resources. The catalog's entries are the publisher's claims, not something agenttru.st verified.
AI use policy
Search: yesAI input: yesAI training: no
What this site's robots.txt says about how AI may use its content. Recorded as the operator wrote it, not enforced — these are preferences about use, not access, and agenttru.st only reads the agent's own discovery documents.
AI-facing documents
Publishes /llms.txt — “Hacker Bob” a curated map of the site's content for language models
Fetched from this host during verification. Neither document is how this agent was discovered.
First seen
21 Sep 2026
View verification details
Assurance
bronze Bronze — agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
? Unknown · Cloudflare, Inc. (AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
Last checked
1d ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of bob-site-5i9.pages.dev controls every word below.

Search public CVE records

Search cleared public Hacker Bob CVE records by identifier, project, or publication status.

cvepublic-recordssearchread-only
Examples it gives
  • Find CVE-2026-47747
  • List public netatalk records

Describe Hacker Bob capabilities

Explain the public interface boundary and how an authorized operator installs the local assessment runtime.

capabilitiesinstallationauthorizationread-only
Examples it gives
  • What can the hosted Hacker Bob interfaces do?
  • How do I install Hacker Bob locally?

What its catalog declares

From the ARD catalog this host publishes at /.well-known/ai-catalog.json. The operator controls every entry; agenttru.st verified that the catalog exists and parses, and nothing about what the entries say.

Hacker Bob agent guide

text/markdowntrust manifest

Short guide to Hacker Bob's public records interfaces, local installation, authorization boundary, and current limits.

https://hackerbob.ai/llms.txt

Hacker Bob agent instructions

text/markdowntrust manifest

When-to-use guidance for the public records interfaces and local assessment runtime, including their separate authorization boundaries.

https://hackerbob.ai/agents.md

Hacker Bob full agent guide

text/markdowntrust manifest

Full public documentation and cleared Common Vulnerabilities and Exposures record index. No remote assessment tools are exposed.

https://hackerbob.ai/llms-full.txt

Hacker Bob public vulnerability records

jsontrust manifest

Read-only, paginated API for cleared public CVE records plus assigned IDs that do not yet have public records.

https://hackerbob.ai/api/v1/cve-records

Hacker Bob public records API

vnd.oai.openapitrust manifest

OpenAPI 3.1 contract for the read-only Hacker Bob public records and capability endpoints.

https://hackerbob.ai/openapi.json

Hacker Bob public records MCP server

jsontrust manifest

Hosted read-only MCP server for cleared public CVE records, capability metadata, and agent instructions.

https://hackerbob.ai/mcp

And 6 more entries in the catalog, not shown here.

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
Hacker Bob — what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.0.0
Card completeness
complete all eight fields required by a2a.proto v1.0
View all card details
Capabilities
extendedAgentCard pushNotifications streaming
Agent card
https://bob-site-5i9.pages.dev/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.