{
  "automatic_evidence_credit": false,
  "coverage": {
    "observed_in_last_48h": 189,
    "share_observed": 1.0,
    "targets_with_observation": 189
  },
  "endpoints": {
    "changes": "https://www.gaipagents.com/v1/free/observatory/changes?since=",
    "corrections": "https://www.gaipagents.com/v1/free/observatory/corrections",
    "lookup": "https://www.gaipagents.com/v1/free/observatory/lookup?url=",
    "method": "https://www.gaipagents.com/observatory",
    "target": "https://www.gaipagents.com/v1/free/observatory/targets/{target_id}"
  },
  "generated_at_utc": "2026-09-28T15:11:19Z",
  "limits": {
    "each_target_at_most_every_hours": 24,
    "max_outbound_requests_per_hour": 400,
    "per_host_min_interval_seconds": 60,
    "targets_per_cycle": 50,
    "user_agent": "GAIP-Observatory/1.0 (+https://www.gaipagents.com/observatory)"
  },
  "manifest_changes": {
    "last_7_days": 0
  },
  "metadata_signal_pattern_rates": {
    "OBS-SIG-001": {
      "NOT_EVALUABLE": 0,
      "PATTERN_NOT_PRESENT": 165,
      "PATTERN_PRESENT": 0,
      "present_rate": 0.0,
      "title": "Invisible or bidirectional-control Unicode characters in names or descriptions"
    },
    "OBS-SIG-002": {
      "NOT_EVALUABLE": 0,
      "PATTERN_NOT_PRESENT": 165,
      "PATTERN_PRESENT": 0,
      "present_rate": 0.0,
      "title": "Instruction-like text in descriptions"
    },
    "OBS-SIG-003": {
      "NOT_EVALUABLE": 114,
      "PATTERN_NOT_PRESENT": 51,
      "PATTERN_PRESENT": 0,
      "present_rate": 0.0,
      "title": "Description names a tool published by a different observed server"
    },
    "OBS-SIG-004": {
      "NOT_EVALUABLE": 163,
      "PATTERN_NOT_PRESENT": 2,
      "PATTERN_PRESENT": 0,
      "present_rate": 0.0,
      "title": "Declared authorization scopes with broad-access wording"
    }
  },
  "neutrality": "Aggregate counts only: no per-target ranking, league table, score of a party or verdict.",
  "notice": "Facts observed by GAIP at the stated time (UTC); they may be out of date. This is not an assessment of safety, quality, security, legality or trustworthiness of any party, and not a recommendation. To request a correction, add a right of reply or opt out, POST to https://www.gaipagents.com/v1/free/observatory/corrections or use https://www.gaipagents.com/contact.",
  "overall_verdicts": null,
  "price_gbp": 0,
  "ranking": null,
  "retention_days": {
    "change_log": 730,
    "correction_requests": 730,
    "status_observations": 180
  },
  "schema_version": "gaip.observatory.v1.summary",
  "sources": [
    {
      "collected": "server.json metadata for the latest version of servers that declare a streamable-http remote; servers with registry status 'deleted' are skipped.",
      "enabled": true,
      "name": "Official MCP Registry (remote servers)",
      "source_id": "official-mcp-registry",
      "terms_basis": "The registry publishes an unauthenticated read-only REST API and its aggregator guidance (https://modelcontextprotocol.io/registry/registry-aggregators) states that aggregators are expected to scrape it on a regular but infrequent basis (e.g. once per hour). GAIP reads at most 3 pages every 6 hours and honours robots.txt (none was published at registry.modelcontextprotocol.io when checked on 2026-09-28).",
      "terms_checked_at": "2026-09-28",
      "url": "https://registry.modelcontextprotocol.io/v0.1/servers"
    },
    {
      "collected": "initialize result (protocol version, server name/version, capability names) and tools/list (names, bounded descriptions, bounded input schemas, annotations).",
      "enabled": true,
      "name": "Remote MCP server endpoints listed in the registry",
      "source_id": "remote-mcp-endpoints",
      "terms_basis": "Operators published these endpoints to a public registry for discovery by MCP clients. GAIP sends only the protocol's discovery handshake (initialize, notifications/initialized, tools/list) that any client sends, never tools/call, never credentials, honours each host's robots.txt for the GAIP-Observatory token and the opt-out list, and contacts each target at most once a day.",
      "terms_checked_at": "2026-09-28",
      "url": null
    },
    {
      "collected": "A2A agent card fields needed for change detection (bounded).",
      "enabled": true,
      "name": "Public A2A agent cards in GAIP's agent readiness index",
      "source_id": "gaip-readiness-index",
      "terms_basis": "Agent cards published at RFC 8615 well-known locations are discovery documents intended for automated clients; each card URL entered the index because a caller asked GAIP to check it. robots.txt and the opt-out list are honoured; one GET per card per day.",
      "terms_checked_at": "2026-09-28",
      "url": "https://www.gaipagents.com/v1/free/agent-readiness"
    },
    {
      "collected": "Agent card and MCP tools/list of each GAIP specialist.",
      "enabled": true,
      "name": "GAIP's ten public specialists (control group)",
      "source_id": "gaip-control",
      "terms_basis": "GAIP's own public surfaces.",
      "terms_checked_at": "2026-09-28",
      "url": "https://www.gaipagents.com/agents"
    }
  ],
  "status_distribution": {
    "AUTHORIZATION_REQUIRED_NOT_ATTEMPTED": 60,
    "HTTP_STATUS_NOT_2XX": 3,
    "OBSERVED": 99,
    "REDIRECT_NOT_FOLLOWED": 1,
    "ROBOTS_DISALLOWED": 24,
    "TOOLS_LIST_HTTP_STATUS_NOT_2XX": 2
  },
  "targets": {
    "by_kind": {
      "A2A_CARD": 40,
      "GAIP_CONTROL": 10,
      "MCP_REMOTE": 139
    },
    "total": 189
  },
  "third_party_scanners": [
    {
      "name": "Snyk agent-scan (formerly Invariant Labs mcp-scan)",
      "status": "NOT_RUN",
      "url": "https://github.com/snyk/agent-scan"
    },
    {
      "name": "Cisco AI Defense MCP Scanner",
      "status": "NOT_RUN",
      "url": "https://github.com/cisco-ai-defense/mcp-scanner"
    }
  ]
}