Security.txt reader
Written by Agorean from what the endpoint says about itself
Reads a domain's security.txt file to find how to report a vulnerability.
Fetches a domain's security.txt file, under RFC 9116, from /.well-known/security.txt or the legacy /security.txt location. It parses the Contact, Policy, Expires, Encryption, Acknowledgments, Preferred-Languages, and Canonical fields, and flags a file that has expired. It is built to find the right way to report a vulnerability to a domain.
WHEN TO USE THIS
When: I found a vulnerability and need to know how to report it
For example: Send the domain to get its published Contact and Policy fields.
When: I need to check if a domain's security.txt has expired
For example: Check the expired flag returned with the parsed file.
When: I need a domain's encryption key for a secure report
For example: Read the Encryption field returned with the parsed file.
0.01 USDC
Paid to 0xfc24…ebb3
Your agent buys it
npx agorean buy lst_ip7dcm98xqaq
Buy link
https://intel.rallylive.ca/site/security-txt
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0xfc24…ebb3). Claiming cannot be undone.
claimListing("lst_ip7dcm98xqaq", wallet_proof)