check_agent_discovery
deepcom.blackveilsecurity/dns · Verify this server
Assess the security posture of IETF BANDAID agent-discovery records (draft-mozleywilliams-dnsop-dnsaid). Detects SVCB agent records under _agents/_index._{protocol}._agents, reports whether the discovery zone is DNSSEC-anchored (unsigned = spoofable agent endpoints), evaluates DANE/TLSA binding trust (RFC 6698 §10.1), and checks capability-document integrity (cap / cap-sha256). Read-only; uses Private-Use SVCB param code points pending IANA assignment.
52 trials · measured 1 day ago
check_agent_discovery scores 38.5/100 on Vouch's measured behaviour index, from 52 real invocation trials against com.blackveilsecurity/dns, measured 6 Oct 2026 under methodology v0.2.0. Its lowest-scoring measured component is Reliability at 0.0/100.
Component breakdown
| Component | Weight | Value |
|---|---|---|
| Reliability | 35% | 0.0 |
| Schema integrity | 25% | not applicable |
| Failure behaviour | 15% | 66.7 |
| Latency | 15% | 100.0 |
| Concurrency | 10% | not applicable |
Tool details
- Transport
- remote
- Credential class
- open
- Input schema
- declared
- Output schema
- declared
- Side-effect classification
- read-only
- Declared input schema
{ "type": "object", "required": [ "domain" ], "properties": { "name": { "type": "string", "maxLength": 63, "minLength": 1, "description": "Resolve a single named agent ({name}.{domain}) instead of enumerating the zone." }, "domain": { "type": "string", "maxLength": 253, "minLength": 1, "description": "Domain to check for published agent-discovery records (e.g., example.com)." }, "format": { "enum": [ "full", "compact" ], "type": "string", "description": "Output verbosity. Auto-detected if omitted." }, "protocol": { "enum": [ "a2a", "mcp", "https" ], "type": "string", "description": "Scope discovery to a single agent protocol index (_index._{protocol}._agents). Omit to sweep the zone." }, "verify_cap": { "type": "boolean", "description": "Fetch each declared capability document (cap=) over HTTPS via safeFetch and verify it against the cap-sha256 integrity pin. Default false (declaration/existence check only)." }, "force_refresh": { "type": "boolean", "description": "Bypass cache and run a fresh check. Useful after DNS changes." } } }
Score history
| Day | Score | Tier | Methodology |
|---|---|---|---|
| 2026-10-06 | 38.5 | deep | v0.2.0 |
| 2026-09-16 | 100.0 | shallow | v0.2.0 |
Probe evidence
| Probe | Outcomes |
|---|---|
| reliability | timeout: 1, error: 19 |
| malformed_input | error: 4 |
| timeout_honour | skipped: 2 |
| cancellation | pass: 2 |
| determinism | error: 4 |
| concurrency | error: 20 |
| schema_integrity | pass: 1 |
Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.
Embed this score
Available for every tool, scored or not — not a verification perk. Always links back to this page.
[](https://vouch.tools/tools/d6035446-50ec-4fc0-ba90-ef1e72f43597)