{"id":"40cb0b16-17d7-46f9-b65b-c2da52b4f0bb","entityType":"agent","slug":"crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4","name":"Crawled www.rfc-editor.org 98b86db2","canonicalUrl":"https://www.xpersona.co/agent/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4","canonicalPath":"/agent/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4","generatedAt":"2026-10-09T17:57:03.160Z","source":"GITHUB_REPOS","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"description":"nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent... nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent session and send it with the initial request to the OpenID Provider (OP). The OP puts the received nonce value into the ID Token that is issued as part of the code exchange at the token endpoint. If an","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/14/2026.","installCommand":null,"sourceUrl":"https://www.rfc-editor.org/rfc/rfc9700","homepage":"https://www.rfc-editor.org/rfc/rfc9700","primaryLinks":[{"label":"View Source","url":"https://www.rfc-editor.org/rfc/rfc9700","kind":"source"}],"safetyScore":84,"overallRank":77.2,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the cl"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No protocol or capability metadata is available."},"protocols":[],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":0,"capabilityMatrix":{"rows":[],"flattenedTokens":""}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-03-14T02:02:15.180Z","emptyReason":null},"lastUpdatedAt":"2026-04-14T23:26:25.608Z","lastCrawledAt":"2026-03-14T02:02:15.180Z","lastIndexedAt":"2026-03-14T02:02:15.180Z","nextCrawlAt":null,"lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":null,"setupComplexity":"medium","setupSteps":["Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":[]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_REPOS","generatedAt":"2026-10-09T17:57:03.160Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-98b86db232912c49d3a4/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"readme":"nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent session and send it with the initial request to the OpenID Provider (OP). The OP puts the received nonce value into the ID Token that is issued as part of the code exchange at the token endpoint. If an attacker injects an authorization code in the authorization response, the nonce value in the client session and the nonce value in the ID Token received from the token endpoint will not match, and the attack is detected. The assumption is that an attacker cannot get hold of the user agent state on the victim's device (from which the attacker has stolen the respective authorization code). ¶ It is important to note that this countermeasure only works if the client properly chec","readmeExcerpt":"nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent session and send it with the initial request to the OpenID Provider (OP). The OP puts the received nonce value into the ID Token that is issued as part of the code exchange at the token endpoint. If an ","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":[],"docsSourceLabel":"GITHUB REPOS","editorialOverview":"nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent... nce OpenID Connect's existing nonce parameter can protect against authorization code injection attacks. The nonce value is one-time use and is created by the client. The client is supposed to bind it to the user agent session and send it with the initial request to the OpenID Provider (OP). The OP puts the received nonce value into the ID Token that is issued as part of the code exchange at the token endpoint. If an","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":465,"uniquenessScore":55,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"agent-directory","verified":false,"confidence":"low","updatedAt":"2026-10-09T17:57:03.160Z","emptyReason":"No close protocol neighbors were found."},"items":[],"links":{"hub":"/agent","source":"/agent/source/github_repos","protocols":[]}}}