Travel Supplier bronze
rogue-supplier.webmesh.ai
“Adversarial test agent: issues flight quotes without enforcing mandate authorization, DPoP proof, or on-chain settlement. ANS-registered (the key IS anchored and the card IS signed), so the auditor's identity_chain check correctly passes; both are legitimate agents. Detection comes from the mandate and receipt layer: a rogue-supplier evidence bundle carries no authority-signed mandate and no SCITT receipt, so audit_transaction returns verdict=invalid on mandate_signature and receipt_anchored.
a2a https://rogue-supplier.webmesh.ai talk to it https://rogue-supplier.webmesh.ai/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Let's Encrypt
domain-validated
Valid until 13 Dec 2026.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified (TLSA query returned RCodeNameError)
- Discovery
-
Well-known document
This host also publishes a DNS-AID
SVCBrecord declaring itself an agent speakinga2a, served with a DNSSEC-validated answer. A declaration is not a verification β the fetch above is what proved it β but it is a deliberate statement by whoever controls the zone.This host also publishes an ARD catalog (/.well-known/ai-catalog.json) declaring 3 resources. The catalog's entries are the publisher's claims, not something agenttru.st verified. - AI-facing documents
-
Publishes a Web Bot Auth key directory (1 key,
Ed25519) β the operator publishes keys so their agent's signed requests can be verified. agenttru.st recorded that the directory exists; it has not verified a signature.Fetched from this host during verification. Neither document is how this agent was discovered. - First seen
- 15 Sep 2026
View verification details
- Assurance
- bronze Bronze β agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
- πΊπΈ US Β· GoDaddy.com, LLC (AS398101)
- Last checked
- 5d ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks β the operator of rogue-supplier.webmesh.ai controls every word below.
Flight Quote
Plausible quotes - broken identity. Expected to fail verification.
- Rogue quote MAD-SIN
What its catalog declares
From the ARD catalog this host publishes at
/.well-known/ai-catalog.json. The operator controls every entry; agenttru.st
verified that the catalog exists and parses, and nothing about what the entries say.
Travel Supplier (A2A)
Adversarial test agent: issues flight quotes without enforcing mandate authorization, DPoP proof, or on-chain settlement. ANS-registered (the key IS anchored and the card IS signed), so the auditor's identity_chain check correctly passes; both are legitimate agents. Detection comes from the mandate and receipt layer: a rogue-supplier evidence bundle carries no authority-signed mandate and no SCITT receipt, so audit_transaction returns verdict=invalid on mandate_signature and receipt_anchored.
https://rogue-supplier.webmesh.ai/.well-known/agent-card.jsonTravel Supplier (MCP)
Rogue supplier MCP server - no valid identity.
https://rogue-supplier.webmesh.ai/.well-known/mcp.jsonWebmesh Agent (NANDA AgentFacts)
Project NANDA AgentFacts: operational profile, adaptive-resolver policies, and governance metadata.
https://rogue-supplier.webmesh.ai/agentfacts.jsonTechnical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- Webmesh β what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 1.0.2
- Auth schemes
- ansIdentityCert httpMessageSignatures noAuth
- Extensions
-
https://modelcontextprotocol.ioRogue supplier MCP server - no valid identity.https://webmesh.ai/ext/ans-trust-stack/v1Identity and interoperability stack: ANS Trust Card (x5c chain + stapled SCITT receipt), DNS-AID SVCB with DNSSEC and DANE TLSA, DNSid organizational accountability, ARD / AI-Catalog discovery, and Web Bot Auth (RFC 9421 HTTP Message Signatures) outbound rA2A protocol extensions the card declares. A declared payment extension (AP2, x402) means the operator says the agent can transact, not that agenttru.st has seen it do so. - Card completeness
- complete all eight fields required by a2a.proto v1.0
View all card details
- Capabilities
- extendedAgentCard extensions pushNotifications streaming
- Agent card
- https://rogue-supplier.webmesh.ai/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.