agenttru.st

Travel Supplier bronze

rogue-supplier.webmesh.ai

Adversarial test agent: issues flight quotes without enforcing mandate authorization, DPoP proof, or on-chain settlement. ANS-registered (the key IS anchored and the card IS signed), so the auditor's identity_chain check correctly passes; both are legitimate agents. Detection comes from the mandate and receipt layer: a rogue-supplier evidence bundle carries no authority-signed mandate and no SCITT receipt, so audit_transaction returns verdict=invalid on mandate_signature and receipt_anchored.

a2a https://rogue-supplier.webmesh.ai talk to it https://rogue-supplier.webmesh.ai/.well-known/agent-card.json its card
πŸ‡ΊπŸ‡Έ US Β· GoDaddy.com, LLC Checked 5d ago extendedAgentCard, extensions, pushNotifications, streaming

we checked this    the operator says this

Community rating 0 0 up Β· 0 down β€” sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Let's Encrypt domain-validated
Valid until 13 Dec 2026.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified (TLSA query returned RCodeNameError)
Discovery
Well-known document
This host also publishes a DNS-AID SVCB record declaring itself an agent speaking a2a, served with a DNSSEC-validated answer. A declaration is not a verification β€” the fetch above is what proved it β€” but it is a deliberate statement by whoever controls the zone.
This host also publishes an ARD catalog (/.well-known/ai-catalog.json) declaring 3 resources. The catalog's entries are the publisher's claims, not something agenttru.st verified.
AI-facing documents
Publishes a Web Bot Auth key directory (1 key, Ed25519) β€” the operator publishes keys so their agent's signed requests can be verified. agenttru.st recorded that the directory exists; it has not verified a signature.
Fetched from this host during verification. Neither document is how this agent was discovered.
First seen
15 Sep 2026
View verification details
Assurance
bronze Bronze β€” agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
πŸ‡ΊπŸ‡Έ US Β· GoDaddy.com, LLC (AS398101)
Last checked
5d ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks β€” the operator of rogue-supplier.webmesh.ai controls every word below.

Flight Quote

Plausible quotes - broken identity. Expected to fail verification.

adversarialtest
Examples it gives
  • Rogue quote MAD-SIN

What its catalog declares

From the ARD catalog this host publishes at /.well-known/ai-catalog.json. The operator controls every entry; agenttru.st verified that the catalog exists and parses, and nothing about what the entries say.

Travel Supplier (A2A)

a2a-agent-cardtrust manifest

Adversarial test agent: issues flight quotes without enforcing mandate authorization, DPoP proof, or on-chain settlement. ANS-registered (the key IS anchored and the card IS signed), so the auditor's identity_chain check correctly passes; both are legitimate agents. Detection comes from the mandate and receipt layer: a rogue-supplier evidence bundle carries no authority-signed mandate and no SCITT receipt, so audit_transaction returns verdict=invalid on mandate_signature and receipt_anchored.

https://rogue-supplier.webmesh.ai/.well-known/agent-card.json

Travel Supplier (MCP)

mcp-server-cardtrust manifest

Rogue supplier MCP server - no valid identity.

https://rogue-supplier.webmesh.ai/.well-known/mcp.json

Webmesh Agent (NANDA AgentFacts)

jsontrust manifest

Project NANDA AgentFacts: operational profile, adaptive-resolver policies, and governance metadata.

https://rogue-supplier.webmesh.ai/agentfacts.json

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
Webmesh β€” what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.0.2
Auth schemes
ansIdentityCert httpMessageSignatures noAuth
Extensions
https://modelcontextprotocol.io
Rogue supplier MCP server - no valid identity.
https://webmesh.ai/ext/ans-trust-stack/v1
Identity and interoperability stack: ANS Trust Card (x5c chain + stapled SCITT receipt), DNS-AID SVCB with DNSSEC and DANE TLSA, DNSid organizational accountability, ARD / AI-Catalog discovery, and Web Bot Auth (RFC 9421 HTTP Message Signatures) outbound r
A2A protocol extensions the card declares. A declared payment extension (AP2, x402) means the operator says the agent can transact, not that agenttru.st has seen it do so.
Card completeness
complete all eight fields required by a2a.proto v1.0
View all card details
Capabilities
extendedAgentCard extensions pushNotifications streaming
Agent card
https://rogue-supplier.webmesh.ai/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.