check_agent_discovery

deep

com.blackveilsecurity/dns · Verify this server

Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, reports whether the discovery zone is DNSSEC-anchored (unsigned = spoofable agent endpoints), evaluates DANE/TLSA binding trust (RFC 6698 §10.1), and checks capability-document integrity (cap / cap-sha256). Read-only; uses Private-Use SVCB param code points pending IANA assignment.

38.5/100

52 trials · measured 1 day ago

check_agent_discovery scores 38.5/100 on Vouch's measured behaviour index, from 52 real invocation trials against com.blackveilsecurity/dns, measured 6 Oct 2026 under methodology v0.2.0. Its lowest-scoring measured component is Reliability at 0.0/100.

Component breakdown

ComponentWeightValue
Reliability35%0.0
Schema integrity25%not applicable
Failure behaviour15%66.7
Latency15%100.0
Concurrency10%not applicable

Tool details

Transport
remote
Credential class
open
Input schema
declared
Output schema
declared
Side-effect classification
read-only
Declared input schema
{
  "type": "object",
  "required": [
    "domain"
  ],
  "properties": {
    "name": {
      "type": "string",
      "maxLength": 63,
      "minLength": 1,
      "description": "Resolve a single named agent ({name}.{domain}) instead of enumerating the zone."
    },
    "domain": {
      "type": "string",
      "maxLength": 253,
      "minLength": 1,
      "description": "Domain to check for published agent-discovery records (e.g., example.com)."
    },
    "format": {
      "enum": [
        "full",
        "compact"
      ],
      "type": "string",
      "description": "Output verbosity. Auto-detected if omitted."
    },
    "protocol": {
      "enum": [
        "a2a",
        "mcp",
        "https"
      ],
      "type": "string",
      "description": "Scope discovery to a single agent protocol index (_index._{protocol}._agents). Omit to sweep the zone."
    },
    "verify_cap": {
      "type": "boolean",
      "description": "Fetch each declared capability document (cap=) over HTTPS via safeFetch and verify it against the cap-sha256 integrity pin. Default false (declaration/existence check only)."
    },
    "force_refresh": {
      "type": "boolean",
      "description": "Bypass cache and run a fresh check. Useful after DNS changes."
    }
  }
}

Score history

DayScoreTierMethodology
2026-10-0638.5deepv0.2.0
2026-09-16100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
reliabilitytimeout: 1, error: 19
malformed_inputerror: 4
timeout_honourskipped: 2
cancellationpass: 2
determinismerror: 4
concurrencyerror: 20
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: check_agent_discovery
[![Vouch score](https://vouch.tools/api/tools/d6035446-50ec-4fc0-ba90-ef1e72f43597/badge.svg)](https://vouch.tools/tools/d6035446-50ec-4fc0-ba90-ef1e72f43597)