{"id":"0116d757-f184-4e64-be68-2da7ca3d8506","entityType":"agent","slug":"crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625","name":"Crawled www.rfc-editor.org c3b3a653","canonicalUrl":"https://www.xpersona.co/agent/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625","canonicalPath":"/agent/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625","generatedAt":"2026-10-09T11:24:43.337Z","source":"GITHUB_REPOS","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"description":"HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be un... HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be unexpected for developers but is defined in Section 15.4.8 of [ RFC9110 ] . This status code (307) does not require the user agent to rewrite the POST request to a GET request and thereby drop the form dat","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/14/2026.","installCommand":null,"sourceUrl":"https://www.rfc-editor.org/rfc/rfc9700","homepage":"https://www.rfc-editor.org/rfc/rfc9700","primaryLinks":[{"label":"View Source","url":"https://www.rfc-editor.org/rfc/rfc9700","kind":"source"}],"safetyScore":84,"overallRank":77.2,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the use"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No protocol or capability metadata is available."},"protocols":[],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":0,"capabilityMatrix":{"rows":[],"flattenedTokens":""}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-03-14T02:02:15.181Z","emptyReason":null},"lastUpdatedAt":"2026-04-14T23:26:25.608Z","lastCrawledAt":"2026-03-14T02:02:15.181Z","lastIndexedAt":"2026-03-14T02:02:15.181Z","nextCrawlAt":null,"lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":null,"setupComplexity":"medium","setupSteps":["Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":[]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_REPOS","generatedAt":"2026-10-09T11:24:43.337Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-3d02f88bc2befb7e2017-c3b3a65336fc63490625/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"readme":"HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be unexpected for developers but is defined in Section 15.4.8 of [ RFC9110 ] . This status code (307) does not require the user agent to rewrite the POST request to a GET request and thereby drop the form data in the POST request body. ¶ In the HTTP standard [ RFC9110 ] , only the status code 303 unambiguously enforces rewriting the HTTP POST request to an HTTP GET request. For all other status codes, including the popular 302, user agents can opt not to rewrite POST to GET requests, thereby causing the user's credentials to be revealed to the client. (In practice, however, most user agents will only show this behavior for 307 redirects.) ¶ Authorization servers that redirect a r","readmeExcerpt":"HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be unexpected for developers but is defined in Section 15.4.8 of [ RFC9110 ] . This status code (307) does not require the user agent to rewrite the POST request to a GET request and thereby drop the form dat","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":[],"docsSourceLabel":"GITHUB REPOS","editorialOverview":"HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be un... HTTP POST to the client. ¶ This discloses the sensitive credentials to the client. If the client is malicious, it can use the credentials to impersonate the user at the authorization server. ¶ The behavior might be unexpected for developers but is defined in Section 15.4.8 of [ RFC9110 ] . This status code (307) does not require the user agent to rewrite the POST request to a GET request and thereby drop the form dat","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":458,"uniquenessScore":56,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"agent-directory","verified":false,"confidence":"low","updatedAt":"2026-10-09T11:24:43.337Z","emptyReason":"No close protocol neighbors were found."},"items":[],"links":{"hub":"/agent","source":"/agent/source/github_repos","protocols":[]}}}