GAIP Agent Observatory
Dated facts about published agent manifests.
GAIP observes public MCP servers and A2A agent cards once a day at most and keeps a hash-chained, receipted record of what their published manifests said and when they changed.
Facts observed by GAIP at the stated time (UTC); they may be out of date. This is not an assessment of safety, quality, security, legality or trustworthiness of any party, and not a recommendation. To request a correction, add a right of reply or opt out, POST to https://www.gaipagents.com/v1/free/observatory/corrections or use https://www.gaipagents.com/contact.
Method
Metadata only: GAIP reads agent cards, the registry's server.json and, for remote MCP servers, the discovery handshake (initialize and tools/list). GAIP never calls a tool, never authenticates, never tests for vulnerabilities and never follows redirects. Each manifest is normalised into a bounded snapshot, personal data is redacted to a hash, and the snapshot hash is compared with the previous one. A change is appended to the Manifest Transparency Log with a History Spine receipt.
Aggregate summary · Change feed · target pages at /v1/free/observatory/targets/{target_id} (find ids with /v1/free/observatory/lookup?url=)
Neutrality
GAIP publishes observed facts (for example “tool description changed” or “endpoint returned HTTP 503 at T”). It does not characterise parties, issue verdicts or scores of parties, or rank or list parties against each other. Metadata signals report only whether a documented pattern is present:
- OBS-SIG-001 Invisible or bidirectional-control Unicode characters in names or descriptions. Zero-width, bidirectional-control and Unicode tag characters are not visible to a human reader but are read by language models. GAIP reports whether any occur; many have ordinary uses.
- OBS-SIG-002 Instruction-like text in descriptions. Tool and skill descriptions are read by models. GAIP reports whether a description contains phrases shaped like instructions to a model (the patterns in GAIP's public conformance rule catalogue, plus the phrases listed in the Observatory method). Such phrases can be benign.
- OBS-SIG-003 Description names a tool published by a different observed server. When a description refers to a tool name that only a different observed server publishes, a model using both servers may connect the two. GAIP reports whether such a reference occurs; shared names are common and often coincidental.
- OBS-SIG-004 Declared authorization scopes with broad-access wording. Declared OAuth scopes whose names contain wildcard or whole-account wording (*, all, admin, root, full) request wide access by name. GAIP reports whether such a scope name is declared; it does not know what the scope grants.
Third-party scanners are listed as not run.
Sources and terms basis
- Official MCP Registry (remote servers): The registry publishes an unauthenticated read-only REST API and its aggregator guidance (https://modelcontextprotocol.io/registry/registry-aggregators) states that aggregators are expected to scrape it on a regular but infrequent basis (e.g. once per hour). GAIP reads at most 3 pages every 6 hours and honours robots.txt (none was published at registry.modelcontextprotocol.io when checked on 2026-09-28).
- Remote MCP server endpoints listed in the registry: Operators published these endpoints to a public registry for discovery by MCP clients. GAIP sends only the protocol's discovery handshake (initialize, notifications/initialized, tools/list) that any client sends, never tools/call, never credentials, honours each host's robots.txt for the GAIP-Observatory token and the opt-out list, and contacts each target at most once a day.
- Public A2A agent cards in GAIP's agent readiness index: Agent cards published at RFC 8615 well-known locations are discovery documents intended for automated clients; each card URL entered the index because a caller asked GAIP to check it. robots.txt and the opt-out list are honoured; one GET per card per day.
- GAIP's ten public specialists (control group): GAIP's own public surfaces.
Opt out
Add User-agent: GAIP-Observatory with Disallow: / to your robots.txt, or send an OPT_OUT request below. Opt-out requests pause collection for the host at once while a person reviews them; the operator also keeps an editable exclusion list.
Corrections and right of reply
POST /v1/free/observatory/corrections with {"kind": "CORRECTION" | "RIGHT_OF_REPLY" | "OPT_OUT", "target_id" or "host", "message"}. Requests are queued for review by a person; no email is sent automatically and no contact details are stored. To be contacted, use Contact and quote the request id.
Retention
Status observations 180 days; change log 730 days (older entries are pruned from the start of the chain, keeping an anchor hash); correction requests 730 days.