{"id":"4f9cca78-8a88-4735-9ec7-8ad90efa7497","entityType":"agent","slug":"crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb","name":"Crawled www.rfc-editor.org 307260d4","canonicalUrl":"https://www.xpersona.co/agent/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb","canonicalPath":"/agent/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb","generatedAt":"2026-10-09T07:44:45.344Z","source":"GITHUB_REPOS","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"description":"utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so... utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so safely. ¶ Section 4.1.2.1 of [ RFC6749 ] already prevents open redirects by stating that the authorization server MUST NOT automatically redirect the user agent in case of an invalid combination of clie","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/14/2026.","installCommand":null,"sourceUrl":"https://www.rfc-editor.org/rfc/rfc9700","homepage":"https://www.rfc-editor.org/rfc/rfc9700","primaryLinks":[{"label":"View Source","url":"https://www.rfc-editor.org/rfc/rfc9700","kind":"source"}],"safetyScore":19,"overallRank":62.8,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect u"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No protocol or capability metadata is available."},"protocols":[],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":0,"capabilityMatrix":{"rows":[],"flattenedTokens":""}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-03-14T02:02:15.181Z","emptyReason":null},"lastUpdatedAt":"2026-04-14T23:26:25.608Z","lastCrawledAt":"2026-03-14T02:02:15.181Z","lastIndexedAt":"2026-03-14T02:02:15.181Z","nextCrawlAt":null,"lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":null,"setupComplexity":"medium","setupSteps":["Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":[]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_REPOS","generatedAt":"2026-10-09T07:44:45.343Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-307260d47af43ca6e1eb/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"readme":" utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so safely. ¶ Section 4.1.2.1 of [ RFC6749 ] already prevents open redirects by stating that the authorization server MUST NOT automatically redirect the user agent in case of an invalid combination of client_id and redirect_uri . ¶ However, an attacker could also utilize a correctly registered redirection URI to perform phishing attacks. The attacker could, for example, register a client via dynamic client registration [ RFC7591 ] and execute one of the following attacks: ¶ Intentionally send an erroneous authorization request, e.g., by using an invalid scope value, thus instructing the authorization server to redirect the user agent to its phishing site. ¶ Intentionally send","readmeExcerpt":"utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so safely. ¶ Section 4.1.2.1 of [ RFC6749 ] already prevents open redirects by stating that the authorization server MUST NOT automatically redirect the user agent in case of an invalid combination of clie","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":[],"docsSourceLabel":"GITHUB REPOS","editorialOverview":"utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so... utilize a user's trust in the authorization server (and its URL in particular) for performing phishing attacks. OAuth authorization servers regularly redirect users to other websites (the clients), but they must do so safely. ¶ Section 4.1.2.1 of [ RFC6749 ] already prevents open redirects by stating that the authorization server MUST NOT automatically redirect the user agent in case of an invalid combination of clie","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":445,"uniquenessScore":58,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"agent-directory","verified":false,"confidence":"low","updatedAt":"2026-10-09T07:44:45.344Z","emptyReason":"No close protocol neighbors were found."},"items":[],"links":{"hub":"/agent","source":"/agent/source/github_repos","protocols":[]}}}