{
  "catalogue_version": "1.0.0",
  "categories": [
    "identity",
    "endpoint",
    "skills",
    "security",
    "metadata"
  ],
  "checked_on": "2026-09-28",
  "checker_report_schema": "gaip.free-conformance-report.v2",
  "description": "Every finding code GAIP's free conformance checker can emit, with severity, category, message template, fix, specification section/URL and the protocol versions it applies to. Only ERROR findings make a report NON_CONFORMANT.",
  "governance": {
    "certification": false,
    "note": "Findings are factual compatibility results for submitted public metadata, not identity, capability or reputation proof.",
    "personal_data": false,
    "public_knowledge_only": true,
    "read_only": true,
    "universal_score": false
  },
  "protocol_specs": {
    "A2A": {
      "current_version": "1.0.0",
      "supported": [
        "0.3.0",
        "1.0"
      ],
      "url": "https://a2a-protocol.org/latest/specification/"
    },
    "MCP": {
      "current_version": "2025-11-25",
      "supported": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ],
      "url": "https://modelcontextprotocol.io/specification/2025-11-25"
    },
    "OPENAPI": {
      "current_version": "3.1.1",
      "supported": [
        "3.0.x",
        "3.1.x"
      ],
      "url": "https://spec.openapis.org/oas/v3.1.1.html"
    }
  },
  "rule_count": 128,
  "rule_sources": {
    "GAIP_POLICY": "GAIP request policy (public, non-personal data; no secrets; no prompt-injection text).",
    "SPEC": "Derived from the published protocol specification."
  },
  "rules": [
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_CAPABILITIES_INVALID",
      "fix": "Replace it with e.g. <value>.",
      "message": "`capabilities` must be an object.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCapabilities",
      "spec_title": "A2A 1.0 \u00a74.4.3 AgentCapabilities",
      "spec_url": "https://a2a-protocol.org/latest/specification/#443-agentcapabilities",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_CAPABILITIES_MISSING",
      "fix": "Add `capabilities`, e.g. <value>.",
      "message": "`capabilities` is missing; the A2A spec requires it (use <value> if the agent supports no optional features).",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCapabilities",
      "spec_title": "A2A 1.0 \u00a74.4.3 AgentCapabilities",
      "spec_url": "https://a2a-protocol.org/latest/specification/#443-agentcapabilities",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_CAPABILITY_FLAG_INVALID",
      "fix": "Set `<value>` to a boolean.",
      "message": "`capabilities.<value>` must be true or false.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCapabilities",
      "spec_title": "A2A 1.0 \u00a74.4.3 AgentCapabilities",
      "spec_url": "https://a2a-protocol.org/latest/specification/#443-agentcapabilities",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_DEFAULT_INPUT_MODES_MISSING",
      "fix": "Add `<value>` as a list of media types, e.g. [\"application/json\"].",
      "message": "`<value>` is not declared, so clients cannot tell which media types the agent accepts or returns; the A2A spec marks it required and strict SDK clients reject the card.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_DEFAULT_MODES_INVALID",
      "fix": "Replace `<value>` with a list such as [\"text/plain\", \"application/json\"].",
      "message": "`<value>` must be a list of media-type strings.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_DEFAULT_OUTPUT_MODES_MISSING",
      "fix": "Add `<value>` as a list of media types, e.g. [\"application/json\"].",
      "message": "`<value>` is not declared, so clients cannot tell which media types the agent accepts or returns; the A2A spec marks it required and strict SDK clients reject the card.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "A2A_DESCRIPTION_INVALID",
      "fix": "Replace `<value>` with a string.",
      "message": "`<value>` must be a non-empty string.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "A2A_DESCRIPTION_MISSING",
      "fix": "Add `<value>`.",
      "message": "`<value>` is missing; the A2A spec requires it and strict SDK clients reject the card without it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "A2A_ENDPOINT_FIELD_NONSTANDARD",
      "fix": "Declare the endpoint in `supportedInterfaces` (and `url` for 0.3 clients).",
      "message": "`endpoint` is not an A2A field; clients look for `supportedInterfaces[].url` (1.0) or `url` (0.3).",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_EXTENSIONS_INVALID",
      "fix": "Replace it with a list of <value> objects.",
      "message": "`capabilities.extensions` must be a list of extension objects.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentExtension",
      "spec_title": "A2A 1.0 \u00a74.4.4 AgentExtension",
      "spec_url": "https://a2a-protocol.org/latest/specification/#444-agentextension",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_EXTENSION_URI_MISSING",
      "fix": "Add the extension's `uri`.",
      "message": "Each extension needs a `uri` identifying it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentExtension",
      "spec_title": "A2A 1.0 \u00a74.4.4 AgentExtension",
      "spec_url": "https://a2a-protocol.org/latest/specification/#444-agentextension",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "A2A_FIELD_NAME_CASE",
      "fix": "Rename it to `supportedInterfaces`.",
      "message": "A2A JSON uses camelCase; `supported_interfaces` will be ignored by most clients.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_FLAG_INVALID",
      "fix": "Set `<value>` to a boolean.",
      "message": "`<value>` must be true or false.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "A2A_HTTPS_ENDPOINT_REQUIRED",
      "fix": "Publish the agent's https JSON-RPC endpoint in `supportedInterfaces` (and `url` for 0.3 clients).",
      "message": "The card declares no absolute https endpoint (`supportedInterfaces[].url` for A2A 1.0, `url` for 0.3), so no client can call the agent.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "A2A_INTERFACE_BINDING_MISSING",
      "fix": "Add `<value>`.",
      "message": "The interface does not say which protocol binding it speaks (JSONRPC, GRPC or HTTP+JSON).",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "A2A_INTERFACE_BINDING_UNRECOGNISED",
      "fix": "Use one of JSONRPC, GRPC or HTTP+JSON.",
      "message": "`<value>` is not a standard A2A binding (JSONRPC, GRPC, HTTP+JSON).",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "A2A_INTERFACE_OBJECT_REQUIRED",
      "fix": "Replace it with <value>.",
      "message": "Each interface must be an object.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "A2A_INTERFACE_URL_INVALID",
      "fix": "Use the public https URL of the endpoint (http, credentials and #fragments are not allowed).",
      "message": "This interface URL is not an absolute https URL without credentials or fragment.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_MEDIA_TYPE_UNRECOGNISED",
      "fix": "Use a registered media type such as text/plain or application/json.",
      "message": "`<value>` is not a media type (type/subtype).",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "A2A_NAME_REQUIRED",
      "fix": "Add a short human-readable `name`.",
      "message": "The agent card has no non-empty string `name`, so clients and registries cannot identify the agent.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "A2A_NO_SKILLS_DECLARED",
      "fix": "Declare at least one skill with id, name, description and tags.",
      "message": "`skills` is empty, so callers and registries cannot see anything this agent does.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "A2A_PREFERRED_TRANSPORT_UNRECOGNISED",
      "fix": "Use one of JSONRPC, GRPC or HTTP+JSON.",
      "message": "`preferredTransport` `<value>` is not JSONRPC, GRPC or HTTP+JSON.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "A2A_PROTOCOL_VERSION_INVALID",
      "fix": "Set it to e.g. \"0.3.0\" or \"1.0\".",
      "message": "`protocolVersion` must be a string.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_PROTOCOL_VERSION_MISSING",
      "fix": "Declare `protocolVersion` (\"0.3.0\" at the top level for 0.3; per interface for 1.0).",
      "message": "No A2A `protocolVersion` is declared, so clients must guess which version of the protocol to speak.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_PROTOCOL_VERSION_UNRECOGNISED",
      "fix": "Use an A2A version such as \"0.3.0\" or \"1.0\" (or check this is really an A2A card).",
      "message": "`<value>` is an MCP-style date version, not an A2A version.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "A2A_PROVIDER_INVALID",
      "fix": "Replace it with <value>.",
      "message": "`provider` must be an object.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentProvider",
      "spec_title": "A2A 1.0 \u00a74.4.2 AgentProvider",
      "spec_url": "https://a2a-protocol.org/latest/specification/#442-agentprovider",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "A2A_PROVIDER_MISSING",
      "fix": "Optionally add `provider` with `organization` and `url`.",
      "message": "No `provider` is declared, so callers cannot see who operates the agent.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "AgentProvider",
      "spec_title": "A2A 1.0 \u00a74.4.2 AgentProvider",
      "spec_url": "https://a2a-protocol.org/latest/specification/#442-agentprovider",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "A2A_PROVIDER_ORGANIZATION_MISSING",
      "fix": "Add the operating organisation's name.",
      "message": "`provider.organization` is required when `provider` is present.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentProvider",
      "spec_title": "A2A 1.0 \u00a74.4.2 AgentProvider",
      "spec_url": "https://a2a-protocol.org/latest/specification/#442-agentprovider",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "A2A_PROVIDER_URL_INVALID",
      "fix": "Set `provider.url` to an https URL.",
      "message": "`provider.url` should be the operator's https website.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentProvider",
      "spec_title": "A2A 1.0 \u00a74.4.2 AgentProvider",
      "spec_url": "https://a2a-protocol.org/latest/specification/#442-agentprovider",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "A2A_SECURITY_NOT_DECLARED",
      "fix": "If the endpoint needs auth, declare `securitySchemes` and a top-level security requirement.",
      "message": "No `securitySchemes` are declared, so callers will assume the endpoint needs no authentication.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "A2A_SECURITY_REQUIREMENTS_INVALID",
      "fix": "Replace `<value>` with e.g. [<value>].",
      "message": "`<value>` must be a list of requirement objects.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "A2A_SECURITY_REQUIREMENT_MISSING",
      "fix": "Add `security` (0.3) or `securityRequirements` (1.0) naming the scheme(s) callers need.",
      "message": "Security schemes are defined but no requirement says which one callers must use.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "A2A_SECURITY_SCHEMES_INVALID",
      "fix": "Replace it with e.g. <value>}.",
      "message": "`securitySchemes` must be an object mapping scheme names to scheme definitions.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "A2A_SECURITY_SCHEME_INCOMPLETE",
      "fix": "Add `<value>` to this scheme.",
      "message": "A `<value>` security scheme needs `<value>` so clients know how to authenticate.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "A2A_SECURITY_SCHEME_INVALID",
      "fix": "Describe the scheme, e.g. <value>.",
      "message": "Each security scheme must be an object.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "A2A_SECURITY_SCHEME_TYPE_UNRECOGNISED",
      "fix": "Set `type` to one of apiKey, http, oauth2, openIdConnect or mutualTLS.",
      "message": "This security scheme has no recognised `type` (apiKey, http, oauth2, openIdConnect, mutualTLS) or A2A 1.0 scheme wrapper, so clients cannot use it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "A2A_SECURITY_SCHEME_UNDEFINED",
      "fix": "Define `<value>` under `securitySchemes` or remove this requirement.",
      "message": "Security requirement references scheme `<value>`, which is not defined in `securitySchemes`, so no client can satisfy it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "A2A_SECURITY_SCHEME_URL_INVALID",
      "fix": "Point it at your https OpenID discovery document.",
      "message": "`openIdConnectUrl` must be an absolute https URL.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "SecurityScheme",
      "spec_title": "A2A 1.0 \u00a74.5.1 SecurityScheme",
      "spec_url": "https://a2a-protocol.org/latest/specification/#451-securityscheme",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "A2A_SIGNATURES_INVALID",
      "fix": "Replace it with a list of <value> objects or remove it.",
      "message": "`signatures` must be a list of JWS objects.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCardSignature",
      "spec_title": "A2A 1.0 \u00a74.4.7 AgentCardSignature",
      "spec_url": "https://a2a-protocol.org/latest/specification/#447-agentcardsignature",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILLS_ARRAY_REQUIRED",
      "fix": "Add `skills` as a list of objects with id, name, description and tags.",
      "message": "`skills` must be a list describing what the agent can do; without it no client can choose a skill.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_DESCRIPTION_INVALID",
      "fix": "Replace it with plain-text prose.",
      "message": "`description` must be a non-empty string.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "A2A_SKILL_DESCRIPTION_MISSING",
      "fix": "Add one or two sentences saying what the skill does and what input it expects.",
      "message": "The skill has no `description`; the A2A spec requires one and LLM-driven clients use it to pick skills.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_EXAMPLES_INVALID",
      "fix": "Replace it with a list of example request strings.",
      "message": "`examples` must be a list of strings.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "A2A_SKILL_EXAMPLES_MISSING",
      "fix": "Optionally add `examples`: a list of example requests.",
      "message": "The skill has no `examples`; example prompts help callers use it correctly.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_ID_DUPLICATE",
      "fix": "Give each skill a unique `id`.",
      "message": "Skill id `<value>` is used more than once, so clients cannot tell the skills apart.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_ID_REQUIRED",
      "fix": "Add a stable, unique `id` such as \"summarise-document\".",
      "message": "Every skill needs a non-empty string `id` so clients can address it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_MODES_INVALID",
      "fix": "Replace `<value>` with a list such as [\"text/plain\", \"application/json\"].",
      "message": "`<value>` must be a list of media-type strings.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_NAME_REQUIRED",
      "fix": "Add a short human-readable `name`.",
      "message": "Every skill needs a non-empty string `name`.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_OBJECT_REQUIRED",
      "fix": "Replace it with an object carrying id, name, description and tags.",
      "message": "skills[<value>] is a <value>, not a skill object.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "A2A_SKILL_TAGS_INVALID",
      "fix": "Replace it with a list of keyword strings.",
      "message": "`tags` must be a list of non-empty strings.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "A2A_SKILL_TAGS_MISSING",
      "fix": "Add a list of short keywords, e.g. [\"search\", \"summarisation\"].",
      "message": "The skill has no `tags`; the A2A spec requires them and registries use them for discovery.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentSkill",
      "spec_title": "A2A 1.0 \u00a74.4.5 AgentSkill",
      "spec_url": "https://a2a-protocol.org/latest/specification/#445-agentskill",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "A2A_SUPPORTED_INTERFACES_INVALID",
      "fix": "Replace `<value>` with a list of <value> objects.",
      "message": "`<value>` must be a list of interface objects.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentInterface",
      "spec_title": "A2A 1.0 \u00a74.4.6 AgentInterface",
      "spec_url": "https://a2a-protocol.org/latest/specification/#446-agentinterface",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "A2A_URL_FIELD_INVALID",
      "fix": "Point `<value>` at an https URL.",
      "message": "`<value>` should be an absolute https URL.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "A2A_VERSION_INVALID",
      "fix": "Replace `<value>` with a string.",
      "message": "`<value>` must be a non-empty string.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "A2A_VERSION_MISSING",
      "fix": "Add `<value>`.",
      "message": "`<value>` is missing; the A2A spec requires it and strict SDK clients reject the card without it.",
      "protocol": "A2A",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "AgentCard",
      "spec_title": "A2A 1.0 \u00a74.4.1 AgentCard",
      "spec_url": "https://a2a-protocol.org/latest/specification/#441-agentcard",
      "versions": [
        "0.3.0",
        "1.0"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "ENDPOINT_DRIFT",
      "fix": "Confirm the change with the operator before calling the new endpoint.",
      "message": "The card's primary endpoint differs from the endpoint you expected.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "EVIDENCE_POISONING_BLOCKED",
      "fix": "Use public https references.",
      "message": "Evidence references may not use data:, javascript: or file: URLs.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "EVIDENCE_REFS_INVALID",
      "fix": "Pass evidence references as strings.",
      "message": "`evidence_refs` must be a list of non-empty strings.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "IDENTITY_BINDING_MISMATCH",
      "fix": "Check you fetched the right card, or correct `declared_identity`.",
      "message": "The identity you declared does not match the card's id/name.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "MCP_AUTH_NOT_DECLARED",
      "fix": "Optionally declare `authentication` (e.g. <value>) so clients know before connecting.",
      "message": "The description does not say whether the server needs authorization.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Authorization",
      "spec_title": "MCP 2025-11-25 Authorization",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "MCP_CAPABILITIES_INVALID",
      "fix": "Replace it with e.g. <value>}.",
      "message": "`capabilities` must be an object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Lifecycle: capability negotiation",
      "spec_title": "MCP 2025-11-25 Lifecycle: Capability Negotiation",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle#capability-negotiation",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_DESCRIPTION_MISSING",
      "fix": "Optionally add `description`.",
      "message": "No description tells callers what the server is for.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severities": [
        "INFO",
        "WARNING"
      ],
      "severity": "INFO",
      "severity_note": "WARNING for MCP Registry server.json (field required there); INFO for server cards and simple descriptions.",
      "spec_section": "Server Card",
      "spec_title": "SEP-2127 MCP Server Cards (proposal, not yet core spec)",
      "spec_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_DESCRIPTION_TOO_LONG",
      "fix": "Shorten the description.",
      "message": "The registry limits `description` to 100 characters.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "MCP_ENDPOINT_RELATIVE",
      "fix": "Publish an absolute https endpoint, or check the card by `url` so GAIP can resolve it.",
      "message": "The endpoint is a relative path; it only resolves against the URL the card was fetched from.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server Card",
      "spec_title": "SEP-2127 MCP Server Cards (proposal, not yet core spec)",
      "spec_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "MCP_ENDPOINT_URL_INVALID",
      "fix": "Use the public https URL of the endpoint.",
      "message": "This endpoint is not an absolute https URL without credentials or fragment.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Transports",
      "spec_title": "MCP 2025-11-25 Transports",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/transports",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "MCP_HTTPS_ENDPOINT_REQUIRED",
      "fix": "Declare the server's public Streamable HTTP endpoint over https.",
      "message": "No absolute https endpoint is declared (`url`, `transport.endpoint` or `remotes[].url`), so no remote client can connect.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Transports",
      "spec_title": "MCP 2025-11-25 Transports",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/transports",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_NAME_MISSING",
      "fix": "Add `name` (or `serverInfo.name` in a server card).",
      "message": "The server description has no name, so clients and registries cannot label it.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Lifecycle: initialization",
      "spec_title": "MCP 2025-11-25 Lifecycle: Initialization",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle#initialization",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "MCP_NO_REMOTE_ENDPOINT",
      "fix": "Add a `remotes` entry if you also host it.",
      "message": "This server is distributed as a local package only; there is no remote endpoint to call or reach-test.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_NO_TOOLS_LISTED",
      "fix": "List the tools the server offers, if any.",
      "message": "The tool list is empty.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "MCP_PACKAGES_INVALID",
      "fix": "Replace it with a list of <value> objects.",
      "message": "`packages` must be a list.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_PACKAGE_INCOMPLETE",
      "fix": "Add the missing package fields.",
      "message": "Each package needs `registryType` (npm, pypi, oci, ...) and `identifier`.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "MCP_PROTOCOL_VERSION_REQUIRED",
      "fix": "Add the MCP revision the server implements.",
      "message": "`protocolVersion` (e.g. \"2025-06-18\") is missing or not a string, so clients cannot negotiate a version.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Lifecycle: version negotiation",
      "spec_title": "MCP 2025-11-25 Lifecycle: Version Negotiation",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle#version-negotiation",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_PROTOCOL_VERSION_UNKNOWN_REVISION",
      "fix": "Check the revision date against the MCP specification.",
      "message": "`<value>` is not a revision GAIP knows (<value>).",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Versioning",
      "spec_title": "MCP Versioning",
      "spec_url": "https://modelcontextprotocol.io/specification/versioning",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_PROTOCOL_VERSION_UNRECOGNISED",
      "fix": "Use a published MCP revision such as \"2025-06-18\".",
      "message": "`<value>` is not an MCP revision date (YYYY-MM-DD).",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Versioning",
      "spec_title": "MCP Versioning",
      "spec_url": "https://modelcontextprotocol.io/specification/versioning",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_REGISTRY_NAME_FORMAT",
      "fix": "Rename to namespace/name using a namespace you can prove you own.",
      "message": "Registry names use reverse-DNS namespace/name form, e.g. io.github.owner/server.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "MCP_REGISTRY_NAME_REQUIRED",
      "fix": "Add `name` such as \"io.github.your-org/your-server\".",
      "message": "server.json needs a `name` in reverse-DNS form (e.g. io.github.owner/server); the registry rejects it otherwise.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_REGISTRY_SCHEMA_MISSING",
      "fix": "Add the registry schema URL you target.",
      "message": "server.json does not declare `$schema`, so tools cannot validate it against the right revision.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "MCP_REMOTES_INVALID",
      "fix": "Replace it with [<value>].",
      "message": "`remotes` must be a list of remote transports.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "MCP_REMOTE_OBJECT_REQUIRED",
      "fix": "Use <value>.",
      "message": "Each remote must be an object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "MCP_REMOTE_TRANSPORT_UNRECOGNISED",
      "fix": "Set `type` to \"streamable-http\".",
      "message": "Remote `type` should be streamable-http (or sse).",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_REPOSITORY_INVALID",
      "fix": "Point `repository.url` at the public source repository.",
      "message": "`repository` should be <value>.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "MCP_SERVER_INFO_INVALID",
      "fix": "Replace it with <value>.",
      "message": "`serverInfo` must be an object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Lifecycle: initialization",
      "spec_title": "MCP 2025-11-25 Lifecycle: Initialization",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle#initialization",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_SERVER_VERSION_MISSING",
      "fix": "Add `serverInfo.version`.",
      "message": "`serverInfo.version` is missing; clients use it to detect upgrades.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Lifecycle: initialization",
      "spec_title": "MCP 2025-11-25 Lifecycle: Initialization",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle#initialization",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "MCP_SSE_TRANSPORT_DEPRECATED",
      "fix": "Offer a streamable-http remote as well.",
      "message": "The HTTP+SSE transport is deprecated in favour of Streamable HTTP.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Transports",
      "spec_title": "MCP 2025-11-25 Transports",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/transports",
      "versions": [
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOLS_ARRAY_REQUIRED",
      "fix": "Replace `tools` with a list of <value> objects.",
      "message": "`tools` must be a list of tool definitions (or the string \"dynamic\").",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOLS_DYNAMIC",
      "fix": "No action needed.",
      "message": "Tools are declared as dynamic (discover with tools/list).",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Server Card",
      "spec_title": "SEP-2127 MCP Server Cards (proposal, not yet core spec)",
      "spec_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOLS_NOT_LISTED",
      "fix": "Optionally list `tools` so registries can index them.",
      "message": "Tools are not listed in the description; clients will discover them with tools/list.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_ANNOTATIONS_INVALID",
      "fix": "Replace or remove `annotations`.",
      "message": "`annotations` must be an object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOL_ANNOTATION_INVALID",
      "fix": "Set `<value>` to a boolean.",
      "message": "`<value>` must be true or false.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOL_DESCRIPTION_MISSING",
      "fix": "Add a one- or two-sentence `description`.",
      "message": "The tool has no description; models rely on it to decide when to call the tool.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_INPUT_SCHEMA_INVALID",
      "fix": "Replace it with <value>}.",
      "message": "`inputSchema` must be a JSON Schema object with \"type\": \"object\".",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOL_INPUT_SCHEMA_MISSING",
      "fix": "Add a JSON Schema object, e.g. <value>}.",
      "message": "The tool has no `inputSchema`; the MCP spec requires one for tools/list.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_NAME_DUPLICATE",
      "fix": "Give each tool a unique name.",
      "message": "Tool name `<value>` appears more than once.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "MCP_TOOL_NAME_FORMAT",
      "fix": "Rename the tool using only those characters.",
      "message": "Tool names should be 1-128 characters of letters, digits, _ - or . for broad client support.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_NAME_REQUIRED",
      "fix": "Add a unique `name`.",
      "message": "Every tool needs a string `name`.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_OBJECT_REQUIRED",
      "fix": "Replace it with <value>.",
      "message": "tools[<value>] is not a tool object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "MCP_TOOL_OUTPUT_SCHEMA_INVALID",
      "fix": "Replace or remove `outputSchema`.",
      "message": "`outputSchema` must be a JSON Schema object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server features: tools",
      "spec_title": "MCP 2025-11-25 Server Features: Tools",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "MCP_TRANSPORT_INVALID",
      "fix": "Replace it with <value>.",
      "message": "`transport` must be an object.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Transports",
      "spec_title": "MCP 2025-11-25 Transports",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/transports",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "endpoint",
      "code": "MCP_TRANSPORT_TYPE_UNRECOGNISED",
      "fix": "Set `transport.type` to \"streamable-http\".",
      "message": "`transport.type` should be streamable-http (or stdio for local servers).",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Transports",
      "spec_title": "MCP 2025-11-25 Transports",
      "spec_url": "https://modelcontextprotocol.io/specification/2025-11-25/basic/transports",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "MCP_URL_FIELD_INVALID",
      "fix": "Point `<value>` at an https URL.",
      "message": "`<value>` should be an absolute https URL.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Server Card",
      "spec_title": "SEP-2127 MCP Server Cards (proposal, not yet core spec)",
      "spec_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
      "versions": [
        "2024-11-05",
        "2025-03-26",
        "2025-06-18",
        "2025-11-25"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "MCP_VERSION_MISSING",
      "fix": "Add `<value>`.",
      "message": "server.json has no `<value>`; the registry requires it.",
      "protocol": "MCP",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "MCP Registry server.json",
      "spec_title": "MCP Registry server.json schema",
      "spec_url": "https://github.com/modelcontextprotocol/registry",
      "versions": [
        "server.json 2025-09 and later"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "METADATA_OBJECT_REQUIRED",
      "fix": "Pass the agent card, MCP server description or OpenAPI document as `metadata`, or pass `url`.",
      "message": "`metadata` must be a JSON object (the card or document).",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "METADATA_TOO_LARGE",
      "fix": "Submit the card only, without embedded assets.",
      "message": "The metadata is larger than <value> KiB.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "endpoint",
      "code": "OPENAPI_HTTPS_SERVER_REQUIRED",
      "fix": "Declare `servers: [<value>]`.",
      "message": "Every `servers` entry must be an object whose `url` is an absolute https URL, and at least one is required.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Server Object",
      "spec_title": "OpenAPI 3.1.1 Server Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#server-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "identity",
      "code": "OPENAPI_INFO_INVALID",
      "fix": "Replace it with <value>.",
      "message": "`info` must be an object.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Info Object",
      "spec_title": "OpenAPI 3.1.1 Info Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#info-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "OPENAPI_INFO_MISSING",
      "fix": "Add `info` with `title` and `version`.",
      "message": "The required `info` object (title, version) is missing.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Info Object",
      "spec_title": "OpenAPI 3.1.1 Info Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#info-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "OPENAPI_INFO_TITLE_MISSING",
      "fix": "Add `info.<value>`.",
      "message": "`info.<value>` is required by the OpenAPI specification.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Info Object",
      "spec_title": "OpenAPI 3.1.1 Info Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#info-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "identity",
      "code": "OPENAPI_INFO_VERSION_MISSING",
      "fix": "Add `info.<value>`.",
      "message": "`info.<value>` is required by the OpenAPI specification.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Info Object",
      "spec_title": "OpenAPI 3.1.1 Info Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#info-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "OPENAPI_NO_OPERATIONS",
      "fix": "Add at least one operation under `paths`.",
      "message": "The document declares no operations an agent can call.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Paths Object",
      "spec_title": "OpenAPI 3.1.1 Paths Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#paths-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "OPENAPI_NO_PATHS",
      "fix": "Add `paths` if agents should call operations.",
      "message": "The document defines no `paths` (allowed in 3.1 with webhooks/components).",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Paths Object",
      "spec_title": "OpenAPI 3.1.1 Paths Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#paths-object",
      "versions": [
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "OPENAPI_OPERATION_DESCRIPTION_MISSING",
      "fix": "Add a `summary` or `description`.",
      "message": "The operation has no summary or description for an agent to reason about.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Operation Object",
      "spec_title": "OpenAPI 3.1.1 Operation Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#operation-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "OPENAPI_OPERATION_ID_DUPLICATE",
      "fix": "Give each operation a unique `operationId`.",
      "message": "operationId `<value>` is not unique; the spec requires uniqueness.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Operation Object",
      "spec_title": "OpenAPI 3.1.1 Operation Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#operation-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "OPENAPI_OPERATION_ID_MISSING",
      "fix": "Add a unique `operationId`.",
      "message": "The operation has no `operationId`; agent tool generators use it as the tool name.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Operation Object",
      "spec_title": "OpenAPI 3.1.1 Operation Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#operation-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "OPENAPI_OPERATION_INVALID",
      "fix": "Replace it with an Operation Object.",
      "message": "Each operation must be an object.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Operation Object",
      "spec_title": "OpenAPI 3.1.1 Operation Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#operation-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "OPENAPI_PATHS_OBJECT_REQUIRED",
      "fix": "Add `paths` describing the operations agents can call.",
      "message": "`paths` must be an object of path items.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Paths Object",
      "spec_title": "OpenAPI 3.1.1 Paths Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#paths-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "OPENAPI_PATH_ITEM_INVALID",
      "fix": "Replace it with an object of operations (get, post, ...).",
      "message": "Each path item must be an object.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Path Item Object",
      "spec_title": "OpenAPI 3.1.1 Path Item Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#path-item-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "skills",
      "code": "OPENAPI_PATH_KEY_INVALID",
      "fix": "Prefix the path with `/`.",
      "message": "Path keys must start with `/`.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Paths Object",
      "spec_title": "OpenAPI 3.1.1 Paths Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#paths-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "metadata",
      "code": "OPENAPI_REF_UNRESOLVED",
      "fix": "Fix the reference or add the referenced component.",
      "message": "This local `$ref` points at nothing in the document.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Reference Object",
      "spec_title": "OpenAPI 3.1.1 Reference Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#reference-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "skills",
      "code": "OPENAPI_RESPONSES_MISSING",
      "fix": "Add at least one response.",
      "message": "OpenAPI 3.0 requires `responses` on every operation.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Responses Object",
      "spec_title": "OpenAPI 3.1.1 Responses Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#responses-object",
      "versions": [
        "3.0.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "OPENAPI_SECURITY_NOT_DECLARED",
      "fix": "Declare components.securitySchemes and `security` if the API needs auth.",
      "message": "No security schemes are declared, so callers will assume the API needs no authentication.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "INFO",
      "spec_section": "Security Scheme Object",
      "spec_title": "OpenAPI 3.1.1 Security Scheme Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#security-scheme-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "OPENAPI_SECURITY_REQUIREMENTS_INVALID",
      "fix": "Replace it with a list of requirement objects.",
      "message": "`security` must be a list.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Security Requirement Object",
      "spec_title": "OpenAPI 3.1.1 Security Requirement Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#security-requirement-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": false,
      "category": "security",
      "code": "OPENAPI_SECURITY_SCHEME_TYPE_UNRECOGNISED",
      "fix": "Set a valid `type`.",
      "message": "Security schemes need `type` apiKey, http, oauth2, openIdConnect or mutualTLS.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "WARNING",
      "spec_section": "Security Scheme Object",
      "spec_title": "OpenAPI 3.1.1 Security Scheme Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#security-scheme-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "OPENAPI_SECURITY_SCHEME_UNDEFINED",
      "fix": "Define `<value>` under components.securitySchemes or remove the requirement.",
      "message": "Security requirement references `<value>`, which is not in components.securitySchemes.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "Security Requirement Object",
      "spec_title": "OpenAPI 3.1.1 Security Requirement Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#security-requirement-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "OPENAPI_V3_REQUIRED",
      "fix": "Convert the document to OpenAPI 3.1 and set `openapi` to \"3.1.0\".",
      "message": "This is a Swagger 2.0 document; GAIP checks OpenAPI 3.x.",
      "protocol": "OPENAPI",
      "rule_source": "SPEC",
      "severity": "ERROR",
      "spec_section": "OpenAPI Object",
      "spec_title": "OpenAPI 3.1.1 \u00a74.8.1 OpenAPI Object",
      "spec_url": "https://spec.openapis.org/oas/v3.1.1.html#openapi-object",
      "versions": [
        "3.0.x",
        "3.1.x"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "PROMPT_INJECTION_PATTERN_BLOCKED",
      "fix": "Rename the key to a plain identifier.",
      "message": "A key name contains text that reads as an instruction to an AI model (for example telling it to disregard earlier guidance, disclose secrets or replace its operating prompt). Agents reading the card could be steered by it.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "PUBLIC_NON_PERSONAL_DATA_REQUIRED",
      "fix": "Set data_classification to PUBLIC.",
      "message": "GAIP only checks public, non-personal metadata.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "security",
      "code": "SECRET_BEARING_FIELD_BLOCKED",
      "fix": "Remove the value from public metadata and rotate it if it was real; declare auth with securitySchemes instead.",
      "message": "A field named like a credential (token, password, secret, private_key, credential) appears in public metadata. Schema properties with those names are fine when they only describe the field.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    },
    {
      "blocks_conformance": true,
      "category": "metadata",
      "code": "SUPPORTED_PROTOCOL_REQUIRED",
      "fix": "Pass protocol A2A, MCP or OPENAPI (or omit it to infer).",
      "message": "`protocol` must be A2A, MCP or OPENAPI.",
      "protocol": "ANY",
      "rule_source": "GAIP_POLICY",
      "severity": "ERROR",
      "spec_section": "GAIP check request",
      "spec_title": "GAIP free conformance check request policy",
      "spec_url": "https://www.gaipagents.com/v1/free/knowledge/conformance-rules",
      "versions": [
        "ALL"
      ]
    }
  ],
  "schema_version": "gaip.conformance-rule-catalogue.v1",
  "severity_semantics": {
    "ERROR": "Violates a MUST in the spec or GAIP's public-data policy; the report is NON_CONFORMANT.",
    "INFO": "Optional improvement; never affects status.",
    "WARNING": "Violates a SHOULD, a field the spec marks required that clients commonly tolerate, or an interoperability hazard."
  }
}