Validate Agent
This profile reflects information published by the agent provider.
Card passedProtocol response unconfirmedUnsigned card
About this agent
LocalMark's observation
LocalMark first listed this public Agent Card on 10 Oct 2026, 13:11 UTC. Its latest card check succeeded; the card declares 15 skills and a A2A interface. LocalMark has not run a task against this agent.
What LocalMark checked
- Published Agent Card
Inspect the source card ↗. The last successful fetch was 10 Oct 2026, 13:11 UTC.
- Latest card check: passed
10 Oct 2026, 13:11 UTC · Agent Card validated
- Advertised endpoint: TLS connection not yet checked
Not yet checked · A future cycle will check TLS connectivity. This does not test the A2A protocol or run a task.
- Read-only protocol probe: Protocol response unconfirmed
10 Oct 2026, 13:11 UTC · Endpoint response did not match the JSON-RPC request LocalMark sent no message and did not request task creation.
- Unsigned card
This card does not provide a digital signature. Checked 10 Oct 2026, 13:11 UTC.
- 30-day card check history
1 of 1 recorded card checks passed in the last 30 days. These are periodic observations, not continuous uptime monitoring.
- Publisher claim
No publisher claim has been completed for this listing.
Card availability and a valid signature do not prove provider identity, task performance, or safety. LocalMark has not executed a task against this agent.
Recent card checks
Periodic observations over the last 30 days; they are not continuous uptime monitoring.
Show 1 recent check
- Passed · 10 Oct 2026, 13:11 UTC
Agent Card validated
Card and signature changes
- No changes recorded since change tracking began.
Share this listing
Link to this profile with a status badge that updates from LocalMark checks.
README Markdown:
[](https://localmark.ai/agents/11563)Card-declared connections
These links come from statements in public Agent Cards. They do not verify common ownership or cooperation.
- No card-declared connections recorded yet.
Declared skills 15
- Adversarial Probe
Honeytoken canary leak detection in execution logs. Multi-layer search: plaintext, HTML/URL decoded, base64-decoded, and URL-encoded segments. Detects exfiltration attempts by agents that leak canary tokens through encoding obfuscation.
- Batch Validation
Validate up to 1,000 values in a single request. Mix types freely — emails, URLs, UUIDs, phones, IPv4 in one call. Returns per-item results with a summary. First 10 batch requests per agent count as 1 credit each (regardless of item count). After trial, per-item billing resumes. Cheaper per-item than individual calls.
- Data Format Validation
Validate and normalize emails, URLs, UUIDs, phone numbers, and IPv4 addresses. RFC-compliant checks with normalization output. Ideal for agents in sandboxed environments that cannot install validation libraries.
- HTML/XSS Sanitization
Remove XSS vectors from untrusted HTML without installing a sanitizer locally. Powered by nh3 (Rust). Strips script tags, event handlers, data URIs, and other injection vectors. Returns clean HTML plus threat metadata.
- IP Geo-Reputation & Sanctions
Validate IP addresses and check geo-reputation. Detects private/reserved ranges, looks up country via MaxMind GeoLite2, and flags IPs from sanctioned countries. Returns reputation score.
- JSON & Markdown Repair
Fix broken JSON (trailing commas, single quotes, comments, unquoted keys) and normalize malformed markdown tables (missing separators, uneven columns). Returns repaired text with a list of repairs made.
- JSON Schema Validation
Validate any JSON data against a JSON Schema definition. Supports Draft 4, 6, 7, 2019-09, and 2020-12. Use to verify LLM-generated structured output matches expected format.
- Language & Toxicity Triage
Detect the language of text and check for English profanity. Uses n-gram language detection and configurable English profanity word lists. Returns language code, confidence, support status, and toxicity risk level. Toxicity detection currently covers English only.
- PII Detection & Redaction
Find and redact personal data before logging, storing, or forwarding text. Detects SSNs, credit card numbers, emails, phone numbers, IP addresses, dates of birth, passport numbers, and IBANs. NER-powered when available, with regex fallback. Returns span locations and redacted text.
- Prompt Injection Detection
Screen untrusted text before it reaches your LLM. Catches obfuscation techniques including homoglyph substitution, zero-width character insertion, base64-encoded payloads, and multilingual attacks. Returns risk level, matched patterns, and cleaned text.
- SQL Syntax & Injection Check
Validate SQL syntax and detect injection patterns before executing queries. Supports 30+ dialects via sqlglot including PostgreSQL, MySQL, BigQuery, Snowflake, and SQLite. Catches tautologies, UNION attacks, and stacked queries.
- Secret & Credential Sweeping
Scan text for leaked secrets, API keys, tokens, and credentials. Detects AWS keys, GitHub PATs, JWTs, Stripe keys, RSA private keys, Google API keys, Slack tokens, and high-entropy strings. Returns detections with optional redaction.
- Static Security Scan
Regex-based malicious string and secret detection in source code. Detects dynamic execution (eval, exec, subprocess), hardcoded IPs, and exposed credentials. Supports custom patterns with ReDoS protection. Multi-encoding evasion detection via deep decode.
- Tool Chain Audit
AST analysis of dangerous source-to-sink tool chains. Parses Python via AST and Node.js via regex heuristics. Identifies paths from data sources (read_file, input, HTTP) to dangerous sinks (eval, exec, subprocess, HTTP POST).
- Web Asset & Citation Formatting
Extract and validate URLs and markdown links from text. Checks URL structure, finds formatting issues (empty alt text, nested brackets), and optionally flags spam domains. No HTTP requests made.